摘要
私钥的安全分发是基于身份密码中一个难以解决的问题。2005年的国际并行分布式系统会议上提出了一种可分离匿名的基于身份的私钥分发方案,简称为SAKI。SAKI基于双线性对运算,结合口令认证机制和盲签名技术,能够在非安全信道中安全地传递用户私钥。经过分析发现SAKI方案缺乏用户私钥申请完整性保护,也不能抵抗对口令的字典攻击。针对SAKI存在的问题,分析了原因并给出了改进后的方案。最后分析了改进方案的安全性,证明改进方案能够克服原方案的缺陷,具有更高的安全性。
Sui,et al. proposed a novel separable and anonymous identity-based key issuing scheme called SAKI based on bilinear pairings. SAKI which uses password authentication and blind signature solves problems of authenticating the user's identity and issuing private keys in identity-based cryptosystems. This paper investigates SAKI and concludes that SAKI is incompetent of pretending the integrity of the message requesting for a private key and is vulnerable against the dictionary attack. A new scheme is proposed ...
出处
《微计算机信息》
北大核心
2008年第6期80-82,共3页
Control & Automation
关键词
基于身份的密码
双线性对
口令认证
盲签名
字典攻击
identity-based cryptography
bilinear pairings
password authentication
blind signaturem
dictionary attack