摘要
本文基于复合问题针对信息保密系统提出了一种双重认证的存取控制方案。该方案与已有类似方案相比要更安全。要攻破该方案,攻击者得同时具有攻破RSA方案和ELGamal方案的能力。在该方案中,用户认证信息不仅用来计算对所需访问文件的存取权,也用于认证需访问保密文件的请求用户的合法性。此外,该方案还能够在动态环境中执行像改变存取权和插入/删除用户或文件这样的存取控制操作,而不影响任何用户的认证信息。
Based on compound problem,this paper proposed an authentication-doubled access control scheme for information protection system.The scheme is safer than the previously proposed schemes.To break this scheme, attacker must be able to break RSA scheme and ELGamal scheme at the same time. In the scheme,the user's authenticating information is used not only for computing the corresponding access privilege to the intended file,but also for authenticating the requesting user not to illegitimately access the protected file.Besides,the scheme can also perform the access control in dynamic environments,such as change access privileges and insert/delete users or files.
出处
《小型微型计算机系统》
CSCD
北大核心
1998年第7期49-52,共4页
Journal of Chinese Computer Systems
基金
湖南省自然科学基金
关键词
复合问题
双重认证
信息保密系统
RSA scheme ELGamal scheme Compound problem Authentication-doubled access control,Information protection system.