摘要
为了防御代理盲签名方案中原始签名者的伪造攻击和签名接收者的伪造攻击,该文对签名算法进行了研究。该文基于新的(t,n)秘密共享机制将证书授权中心(Certificate authority,CA)私钥进行分存,使用其身份作为私钥份额的标识,提供私钥保护的容侵性。该方案不是从保护系统或检测入侵出发来保证CA的安全,而是确保当少数部件被攻击或占领后,CA系统的机密信息并没有暴露。研究结果表明:系统中即使一定数量的用户被恶意攻击者攻击后,系统仍可有效地运转。
To defend the forgery attacks of the original signer and signature receiver in the scheme of proxy blind signature,this paper studies the problem of the signature algorithm. Based on the new(t,n) secret sharing mechanism,the private key of the Certificate Authority( CA) is separately stored by using its identity as the mark of private key so that it can provide the intrusion tolerance for the securing Private Keys. Rather than preventing intrusions or attacks to ensure safety of CA,the project ensures that the confidential information of the CA system will not be exposed when a minority of components are attacked. The research results show that even if certain users are spitefully attacked,the system still works properly.
出处
《南京理工大学学报》
EI
CAS
CSCD
北大核心
2015年第1期34-38,共5页
Journal of Nanjing University of Science and Technology
基金
国家自然科学基金(31270577)
关键词
离散对数
容忍入侵
可撤销匿名性
基于身份
私钥保护
代理盲签名
discrete logarithm
intrusion tolerance
anonymity-revoking
identity-based
securing private keys
proxy blind signature