摘要
针对目前可信计算平台直接匿名认证(DAA)机制的不足,提出一种改进的匿名认证方案。该方案先采用CA验证示证者的EK证书,协助示证者和DAA颁布者各自生成会话密钥,使DAA颁布者能够为示证者颁发秘密的DAA证书;然后示证者用两承诺值相等协议及CFT证明协议来证明承诺值位于某个特定区间的方法,向验证者证明其平台的真实合法性。分析表明,该方案具有较高的安全性,还具备不可欺骗性、匿名性、撤消性,效率更高。
An improved scheme was proposed against the shortage of current mechanism of direct anonymous attestation(DAA) in trusted computing platform.This scheme firstly adopted the CA to verify the EK certificate of prover to help prover and DAA issuer building the session key respectively.The DAA issuer can issue the secret certificate to the prover with the key.Then the prover used a committed number lying in a specific interval to attest the validity to the verifier by integrating the protocol that two committed numbers are equal with the protocol of the CFT proof.The analy-sis shows that this scheme not only has a higher security,but also is non-fraudulence,anonymity,can be withdrawed and more efficiency.
出处
《计算机科学》
CSCD
北大核心
2012年第8期111-114,共4页
Computer Science
基金
广东省高等学校人才引进专项资金项目(粤财教[2010]343号)
肇庆市科技创新计划项目(2011G212)资助
关键词
直接匿名认证
可信计算
零知识证明
网络安全
Direct anonymous attestation
Trusted computing
Zero-knowledge proof
Network security