摘要
数据在共享和使用中面临着恶意攻击、供应链漏洞、安全产品缺陷、技术人员窃取等安全威胁.采用认证网关和密码机对用户身份进行认证,并对数据进行机密性完整性保护,能够增加安全性.但还存在内部威胁,如管理员被收买或内部终端被黑客控制,绕过安全防护机制.针对这些威胁,提出了基于SM9属性加密封装密钥,实现数据共享应用中不出现明文数据、有效应对系统管理员窃密等内部威胁.
Data sharing and applications are faced with malicious attacks,supply chain vulnerabilities,security product defects,technical personnel theft and other security threats.It can improve security by deploying a security authentication gateway and cryptographic server to authenticate user identity and protect data confidentiality and integrity.However,there are also internal threats.For example,the administrator being bought or the internal terminal is controlled by hackers,which will bypass these security protection mechanisms.In view of these threats,this paper proposes an attributebased encryption strategy to encapsulate the key based on SM9,so as to avoid the plaintext data in data sharing applications and effectively deal with internal threats such as theft by system administrators.
作者
王森
许涛
李金贵
Wang Sen;Xu Tao;Li Jingui(Department of Information and Network Security,State Information Center,Beijing 100045;Department of Public Technical Service,State Information Center,Beijing 100045)
出处
《信息安全研究》
CSCD
2023年第11期1061-1066,共6页
Journal of Information Security Research
关键词
数据安全
商用密码
身份认证
访问控制
数据加密
属性加密
SM9
data security
commercial cryptography
identity authentication
access control
data encryption
attributebased encryption
SM9