期刊文献+

面向Web服务的SAML路径验证协议及其性能分析 被引量:1

SAML Path Verification Protocol for Web Service and its Performance Analysis
下载PDF
导出
摘要 基于PKI的签名机制在保护SAML断言传递时存在增加SOAP消息长度、显著降低Web服务响应速度的问题。为此,提出了基于身份聚合签名的SAML路径验证(IBASPV)协议,该协议通过缩短SOAP消息中签名值和验证公钥的长度来减少SOAP消息的传输时间,提高服务响应速度。采用SVO逻辑形式化证明了IBASPV协议具有断言完整性、源不可伪造性、传递路径不可篡改和抗重放攻击的安全特性。然后,采用安全模块Rampart测试分析了密码运算时间和数据传输时间随网络数据传输速率的变化趋势,比较了基于IBASPV协议与基于PKI签名的服务认证调用协议的性能。 To resolve the problem of increasing the length of SOAP message and reducing the respond speed of Web service seriously during the PKI-based signature to protect the SAML assertion, the paper proposed the SAML path verification protocol based on identity aggregate signature(IBASPV), which improveds the respond speed of Web serv- ice by shortening the length of the signature and the public key to reduce the transport time of SOAP message. By using SVO logic,we proved that the IBASPV protocol can ensure the integrity of the SAML assertion and source unforge- ability, and can protect the transmission path which can not be tampered with, and can prevent anti-replay attacks. By measuring the cryptographical calculation time and transport time based on Rampart module, we analyzed the trend that these factors which cause response time increase with the network data transport speed. Finally,we compared the per- formance of Web service based IBASPV protocol with that based on PKI signature.
作者 张斌 王曦
出处 《计算机科学》 CSCD 北大核心 2013年第3期192-196,共5页 Computer Science
基金 国家973重点基础研究发展计划(2011CB311801)资助
关键词 Web服务认证 SAML 基于身份的聚合签名 SVO逻辑 性能分析 Web service authentication, SAML, Identity-based aggregate signature, SVO logic, Performance analysis
  • 相关文献

参考文献10

  • 1OASIS.Assertions and Protocols for the OASIS Security Assertion Markup Language(SAML) V2.0[S].2005.
  • 2OASIS identifier:wss-v1.1-spec-os-SOAPMessage Security,Web Services Security:SOAP Message Security 1.1[S].2006.
  • 3Gentry C,Ramzan Z.Identity Based Aggregate Signatures[C] //Proc.of Public Key Cryptography.Springer,2006.
  • 4Syverson P,Van Oorschot P.On Unifying Some Cryptographic Protocol Logics[C] //IEEE Computer Society Symposium on Principles of Distributed Computing.ACM Press,1994,5:14-28.
  • 5Michael C.Pairing Calculation on Supersingular Genus 2 Curves[C] //Proc.of SAC'06.2006.
  • 6Rodrigues D,Estrella J C.Analysis of security and performance aspects in service-oriented architectures[J].International Journal of Security and its Applications,2011,5 (1):13-30.
  • 7The Apache Rampart Project[Z].http://axis.apache.org/axis2/java/rampart,2011.
  • 8Berreto.A Note on Efficient compution of cube roots in charateristic3[EB/OL].http://eprint.jacr.org/2004/305,2004.
  • 9Zhao M,Smith S,Nicol D.Aggregated Path Authentication for Efficient BGP Security[C] //ACM Conference on Computer and Communication Security.Alexandria,USA,2005:128-138.
  • 10Akamai.State of Internct report[R].http://www akamai.com/stateofinternetreport/,2011.

同被引文献8

引证文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部