摘要
个性化服务系统为每个用户提供了满足个性化需求的差异服务,但用户模型的建立和更新依赖于用户的个人信息,存在着隐私泄漏的风险,从而降低了用户使用个性化服务的意愿。本文基于可信计算环境下直接匿名证言方案的可变假名机制,设计了一个面向通用网络环境下个性化服务的匿名认证方案,并针对付费系统的匿名保持问题做了进一步改进。理论分析和实验结果表明,个性化服务提供者可以鉴别用户是否合法付费用户,并具有何种访问权限,但无法确定用户的具体身份,即使服务提供者将访问信息泄漏,也不会危及用户隐私。
Personalized service system provides differential services that satisfy the personalized needs of users. However, both generating and updating users' models depend on private information, thus disclosure of privacy is possible. This could limit users' willingness to use these personalized services. Basing on the pseudonymity of direct anonymous attestation scheme, this paper proposes an anonymous authentication method for personalized service in general networks. Some fringe improvements are also done for holding anonymity in a toll system. Theoretical analysis and experimental results demonstrate that the service provider can know whether a user is regular, and which access right the user has, but it cannot identify the user. Even if the service provider reveals access information, users' privacy will not be endangered.
出处
《计算机科学》
CSCD
北大核心
2008年第4期248-251,共4页
Computer Science
基金
河南省自然科学基金项目(0511014300)
国家"863"高技术研究发展计划项目(200AA142170)
关键词
个性化服务
等级会费制
隐私保护
匿名认证
Personalized service, Graded fee system, Privacy protection, Anonymous authentication