摘要
为了提高基于身份加密体制的用户密钥安全性,解决基于身份加密体制中的密钥托管问题成为一个重要课题。提出了一种针对Boneh-Boyen1基于身份加密体制的安全密钥分发方案,方案中系统的主密钥分片分别保存于一个密钥生成中心和多个密钥隐私中心处,用户的私钥生成需要用户收到密钥生成中心和密钥隐私中心发来的多个私钥分片,以避免密钥生成中心获取用户的私钥。在标准模型中证明了密钥分发方案能够保证密钥生成中心无法获取用户的私钥,能够有效解决Boneh-Boyen1基于身份加密方案的密钥托管问题。
By making use of user's identity as his public key, identity based cryptosystems have many advantages over traditional PKI based cryptosystems. But identity based cryptosystems also have an inherent drawback of key escrow that the key generation center knows all private keys of users. To improve the security of keys in identity based encryption, how to avoid key escrow problem in identity based encryption becomes a hot issue. A secure key issuing scheme for Boneh-Boyenl identity based encryption was proposed, in which multiple key privacy authorities are set in addition to the key generation center to protect the privacy of users' private keys. A rigorous security proof in standard model of our secure key issuing protocol was also given. Thus identity based encryption is more usable in practice.
出处
《计算机科学》
CSCD
北大核心
2012年第B06期35-37,50,共4页
Computer Science