摘要
自动信任协商是一种新型的访问控制方法。在协商过程中,双方的交互信息(证书,策略)具有敏感性。在安全级别要求较高的应用环境下,对信任协商过程中的敏感信息进行安全防护具有重要意义。针对基于密码体制敏感资源安全防护方法进行了系统的分析,总结了各机制的安全特性和优缺点,并对其未来发展趋势进行了展望。
Automated trust negotiation is the rising method of access control.Some information (credential, policy) is private in the communication of trust negotiation.So it is very important to protect privacy information under the high security required environment.This paper analyze the latest privacy-preservation schemes based on cryptography.The character of security、excellence and pitfalls in these schemes are summarized.Finally the development trend for privacy-preservation in ATN is proposed.
出处
《计算机安全》
2009年第7期14-19,共6页
Network & Computer Security
关键词
自动信任协商
敏感信息
隐藏证书
无记忆属性证书
automated trust negotiation
privacy information
hidden credential
oblivious attribute certificates