摘要
Joux提出的三方密钥协商方案虽然简洁、高效,但不能抵抗中间人攻击。基于无证书公钥密码体制,提出一种新的无证书可认证多方密钥协商方案,新方案将Joux的三方协议拓展至多方,并且具有认证功能。由于新方案中所用的签名为短签名,所以整个认证过程计算效率较高,另外,新方案还具有简单证书管理、无密钥托管的优点,新方案满足无密钥控制、抗中间人的主动攻击、前向安全性和抗密钥泄露伪装攻击等多种安全特性。
The tripartite key agreement protocol that Joux has proposed is more efficient and simple, but it is vulnerable to man-in-the-middle attack. A new method based on certificateless authenticated key agreement protocols is proposed, which extends tripartite key agreement to multi-party accompanied by its authentication function. It has a lot of advantages, such as a short signature, high calculation efficiency, simple management about certificate and escrow-free anonymous key. The new method enjoys much secure prosperity, for instance, which has a non-key control and forward security, resists man-in-the- middle and leaked disguise attack, and so on.
出处
《信息技术》
2013年第7期98-100,105,共4页
Information Technology
关键词
密钥协商
认证
无证书密码体制
双线性对
key agreement
authentication
certificateless cryptography
bilinear pairing