期刊文献+

主从区块链容错异构跨域身份认证方案 被引量:7

Master-Slave Blockchain Fault-Tolerant Heterogeneous Cross-Domain IdentityAuthentication Scheme
下载PDF
导出
摘要 异构跨域身份认证是对不同体制信任域内的节点进行身份确认和安全信息交互的技术,现有的认证方案主要存在单点攻击风险和认证复杂等问题。为此,设计了主从区块链身份认证模型和匹配使用的分层拜占庭容错算法,通过主从链分步、分阶段共识,减少了共识参与节点数量,并将PKI体制与CL-PKC体制的特有功能节点与主从链节点相对应,在不改变原有信任域节点功能的前提下,使用区块链证书的哈希值高效传递信任,优化了认证流程,实现了双向异构跨域身份认证。最后通过仿真实验验证以及安全性和性能分析,表明该方案与相关方案对比,在实现安全通信的同时,提高了共识效率和容错性,降低了认证过程的通信开销。 Heterogeneous cross-domain identity authentication is a technology that performs identity confirmation and security information exchange for nodes in different institutional trust domains.The existing authentication schemes mainly have issues such as single-point attack risk,complex authentication.This paper designs a master-slave blockchain identity authentication model and a hierarchical Byzantine fault-tolerant algorithm for matching.Through the step-by-step and phase-by-phase consensus of the master-slave chain,the number of nodes participating in the consensus is reduced.The unique function nodes of the PKI system and the CL-PKC system correspond to the master-slave chain nodes.On the premise of not changing the function of the original trusted domain node,the hash value of the blockchain certificate is used to efficiently transmit trust,and the authentication is optimized.The process realizes two-way heterogeneous cross domain identity authentication.In the end,through the simulation experiment and the analysis of security and perfor-mance,the result shows that compared the mentioned scheme with others,consensus efficiency and fault tolerance are improved,and communication overhead is reduced while ensuring secure communication.
作者 赵平 王赜 李芳 孙士民 ZHAO Ping;WANG Ze;LI Fang;SUN Shimin(School of Computer Science and Technology,Tiangong University,Tianjin 300384,China)
出处 《计算机工程与应用》 CSCD 北大核心 2022年第22期79-88,共10页 Computer Engineering and Applications
基金 国家自然科学基金(61702366,61802281) 天津市重点项目基金(15ZXHLGX003901) 天津市自然科学基金(19JCYBJC15800)。
关键词 区块链 容错算法 跨域身份认证 AVISPA工具 blockchain fault-tolerant algorithm cross-domain authentication AVISPA tool
  • 相关文献

参考文献10

二级参考文献92

  • 1路晓明,冯登国.一种基于身份的多信任域网格认证模型[J].电子学报,2006,34(4):577-582. 被引量:32
  • 2彭华熹.一种基于身份的多信任域认证模型[J].计算机学报,2006,29(8):1271-1281. 被引量:57
  • 3Clark J,van Oorschot P C.SoK:SSL and HTTPS:Revisiting past challenges and evaluating certificate trust model enhancements. 20131EEE Symposium on Security and Privacy (SP) . 2013 被引量:1
  • 4Yang, Hao,Osterweil, Eric,Massey, Dan,Lu, Songwu,Zhang, Lixia.??Deploying Cryptography in Internet-Scale Systems: A Case Study on DNSSEC(J)IEEE Transactions on Dependable and Secure Computing . 2011 (5) 被引量:1
  • 5Rishab Nithyanand,Gene Tsudik,Ersin Uzun.??User-aided reader revocation in PKI-based RFID systems(J)Journal of Computer Security . 2011 (6) 被引量:1
  • 6Massimiliano Pala,Sean W. Smith.??Finding the PKI needles in the Internet haystack(J)Journal of Computer Security . 2010 (3) 被引量:1
  • 7David W. Chadwick,Sean Antony,Rune Bjerk.??Instant certificate revocation and publication using WebDAV(J)Journal of Computer Security . 2010 (3) 被引量:1
  • 8Dimitrios Lekkas,Dimitris Gritzalis.??e-Passports as a means towards a Globally Interoperable Public Key Infrastructure(J)Journal of Computer Security . 2010 (3) 被引量:1
  • 9Gabriel López Millán,Manuel Gil Pérez,Gregorio Martínez Pérez,Antonio F. Gómez Skarmeta.??PKI-based trust management in inter-domain scenarios(J)Computers & Security . 2009 (2) 被引量:1
  • 10Cooper D,Santesson S,Farrell S W, et al.Internet X.509 public key infrastructure certificate and certificate revocation list (CRL) profile. RFC5280 . 2008 被引量:1

共引文献269

同被引文献91

引证文献7

二级引证文献13

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部