期刊文献+

一种细粒度的属性证书出示方案

Fine-grained Disclosure Scheme for Attribute Certificate
下载PDF
导出
摘要 针对现有X.509v4属性证书在细粒度出示部分属性后无法验证合法性的情况,提出了一种支持属性细粒度出示的证书方案。该方案由属性权威对证书中所有属性进行预处理,并对预处理结果生成签名;证书拥有者能够根据不同的应用场合移除证书中不相关属性,并计算验证证书必需的额外信息;验证方根据这些额外信息及证书中的签名能有效地验证被出示部分属性的合法性。该方案与现有标准兼容,并具有灵活性好、安全性高及付出额外开销小等特点。 In order to effectively verify X.509v4 attribute certificate after part of attributes is removed,a fine-grained disclosure scheme is proposed.In this scheme,every attribute in certificate is pretreated,and digital signature of the pretreated results was generated by attribute authority.In different scenarios,uncorrelated attributes is removed from certificate and essential validation information is calculated by certification owner.The validation information and digital signature in certificate can be used to validate legitimacy of the attributes disclosed.The scheme has some characteristics as follows:strong compatibility,good flexibility,high security and little additional cost.
出处 《计算机科学》 CSCD 北大核心 2012年第10期94-98,130,共6页 Computer Science
基金 国家863计划项目(2006AA01Z457 2009AA01Z438) 国家973重点基础研究发展计划(2011CB311801) 河南省科技创新人才计划(114200510001)资助
关键词 属性证书 细粒度 双重签名 隐秘特征属性 哈希树 Attribute certificate Fine-grained Dual signature Dark feature attribute Hash tree
  • 相关文献

参考文献13

  • 1ITU-T. ISO/IEC9594-8 Rec. X. 509 The Directory: Authentica- tion Framework[S]. 2000.
  • 2Nykaen O. Attribute Certificate in X. 509 [EB/OL]. http:// www. hut. fi/-tpny-kane/netsec/final,2000.
  • 3Chadwick D W, Otenko O. The PERMIS X. 509 Role Based Privilege Management Infrastructure[C]//Proceedings of SAC- MAt'02. Monterey, California, USA, 2002.
  • 4Blaze M, Feigenbaum J, Lacy J. Decentralized Trust Manage- ment[C]//Proeeedings of the 17th Symposium on Security and Privacy. Oakland:IEEE Computer Society Press, 1996:164-173.
  • 5Winsborough W H,Seamons K E,Jones V E. Automated Trust Negotiation[C]//Proeeedings of DARPA Information Surviva- bility Conference and Exposition. IEEE Press, 2000:88-102.
  • 6Persiano P, Visconti I. User Privacy Issues Regarding Certifi- cates and the TLS Protocol[C]//Proceedings of 7th ACM Con- ference of Computer and Communications Security Athens. Greece, November 2000.
  • 7廖俊国,洪帆,李俊,杨木祥.在信任协商中保密证书的敏感属性[J].通信学报,2008,29(6):20-25. 被引量:7
  • 8廖俊国,凌乐真,朱彬.一种灵活实用的数字证书中敏感属性保密方案[J].计算机科学,2010,37(6):128-130. 被引量:2
  • 9龚俭,吴桦,杨望.计算机网络安全导论[M].南京:东南大学出版社,2007:253-271.
  • 10肖淑婷,吴国新,孙啸寅.支持属性选择性披露的ATN证书描述方案[J].计算机工程,2010,36(9):142-144. 被引量:2

二级参考文献38

  • 1张荣清,李建欣,怀进鹏.网格计算环境中的安全信任协商系统[J].北京航空航天大学学报,2006,32(3):347-351. 被引量:4
  • 2龚俭,吴桦,杨望.计算机网络安全导论[M].南京:东南大学出版社,2007:253-271.
  • 3Winsborough W H,Seamons K E,Jones V E.Automated Trust Negotiation[C]//Proceedings of DARPA Information Survivability Conference and Exposition.[S.l.]:IEEE Press,2000:88-102.
  • 4Bartel M,Boyer J,Fox B,et al.XML Signature Syntax and Processing(2nd Edition)[EB/OL].[2008-06-10].http://www.w3.org/TR/2008/REC-xmldsig-core-20080610/.
  • 5Imamura T,Dillaway B,Simon E.XML Encryption Syntax and Processing[EB/OL].(2002-12-10).http://www.w3.org/TR/xmlenc-core/.
  • 6Li Jiangtao, Li Ninghui, Winsborough W H. Automated Trust Negotiation Using Cryptographie Credentials [C] // Proceeding of the 12^th conference on computer and communications security. Alexandria, Virginia, USA. ACM Press, November 2005: 46-57.
  • 7Yu Ting, Winslett M, Seamons K E. Supporting Structured Credentials and Sensitive Policies through Interoperable Strategies for Automated Trust Negotiation[J]. ACM Transactions on Information and System Security (TISSEC), 2003,6 (1) : 1-42.
  • 8Li Ninghui, Du Wenliang, Boneh D. Oblivious Signature-Based Envelope [C]// Proceedings of the 22^nd ACM Symposium on Principles of Distributed Computing (PODC 2003). ACM Press, July 2003 : 182-189.
  • 9Winsborough W H, Li Ninghui. Protecting Sensitive Attributed in Automated Trust Negotiation [C] // Proceedings of the 1st ACM Workshop on Privacy in the Electronic Society. ACM Press, 2002 : 41-51.
  • 10Holt J E,Bradshaw R W, Seamons K E, et al. Hidden Credentials [C]//Proceedings of the 2^nd ACM Workshop on Privacy in the Electronic Society. Washington, DC. ACM Press, October 2003 : 1-8.

共引文献12

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部