摘要
在基于传统秘密共享的Web服务中,入侵者可长时间攻击,降低了系统的可靠性,不再适用。本文提出了一种基于主动秘密共享的Web服务器入侵容忍方案,并给出了改进可验证秘密共享方案后的影子产生算法和更新算法。该方案在不改变共享Web服务器私钥的情况下,周期性地更新私钥影子并且销毁原来的影子值,使得入侵者的可利用时间缩短在一个周期内,从而保证Web私钥的长期安全性。
The Web server scheme based on traditional secret shanng is not applicable because the adversary has so much time to mount attacks that this will reduce the dependability. This paper presents a Web server system based on proactive secret sharing, and provides share initialization and renewal algorithms with an improved verifiable secret sharing scheme. This system proposes an effective scheme maintaining the long-time security of Web server private keys, where shares are periodically renewed without changing the shared key and previous shares are all erased in such a way that the available time for the adversary will be reduced to a single time period.
出处
《计算机工程与科学》
CSCD
2006年第8期34-35,49,共3页
Computer Engineering & Science
基金
国家自然科学基金资助项目(60273075)
关键词
入侵容忍
主动秘密共享
WEB安全
intrusion tolerance
proactive secret sharing
Web security