摘要
提出一种基于属性的信任协商方法。协商的双方首先交换包含多个加密属性的信任证书,然后双方根据自己的访问控制策略多次交换密钥逐步向对方显示出自己的属性。在这种协商方法中,双方可以控制自己的信任书中属性值的出示,且该协商方法使用椭圆曲线密钥交换算法产生会话密钥,计算量比较小。
In this paper,an approach to attribute- based automated trust negotiation is proposed that can build up the trust between the entities. Both the client and the system exchange the credential which includes some encrypted attributes as requested by the access control strategy, which is guided by the trust negotiation strategy and disclose their own sensitive attributes gradually. Both the client and the system can control the disclosure of attribute values in the credential, and the approach to automated trust negotiation generate the session key by the elliptic curve key - Exchange algorithm, so the task of calculation is small.
出处
《计算技术与自动化》
2008年第4期118-121,共4页
Computing Technology and Automation
基金
福建省科技发展计划基金资助项目(2007F5071)
关键词
信任协商
属性证书
密钥协商
trust negotiation
attribute certificate
key agreement