摘要
针对目前云环境下LBS的应用,在敏感身份信息和实时位置信息两方面存在的安全隐患,提出对称和非对称混合的加密方案,建立基于该保护方案的LBS安全模型。该模型利用移动用户IMSI的假名标识作为用户唯一身份,避免了敏感身份信息以明文形式传输和存储。在不引入第三方CA的前提下,通信双方采取相异的加密方法,保证了身份和位置信息在无线网络传输和云端存储的安全。最后,通过安全性分析和方案指标比较验证了方案的可行性和有效性。
Aiming at the security pitfall of LBS applications in cloud environment in two aspects of sensitive identity information and real- time position information, we put forward a hybrid symmetrical and asymmetric encryption scheme, and establish the LBS security model based on the protection of that scheme. This model uses the pseudonym logo of IMSI as the only identity of a user, which avoids the transmission and storage of sensitive identity information in plain texts form. In the premise of not introducing the third party CA, both sides in communication take different encryption methods, this guarantees the safety of identity and location information transmitted in wireless network and stored on cloud. Finally, the feasibility and effectiveness of the method is validated through security analysis and scheme indexes comparison.
出处
《计算机应用与软件》
CSCD
北大核心
2013年第8期73-77,共5页
Computer Applications and Software
基金
国家高技术研究发展计划项目(2009AA012201)