计算机科学 ›› 2012, Vol. 39 ›› Issue (10): 94-98.

• 计算机网络与信息安全 • 上一篇    下一篇

一种细粒度的属性证书出示方案

王 凯,张红旗,任志宇,姜皇勤   

  1. (信息工程大学 郑州450004);(河南省信息安全重点实验室 郑州450004)
  • 出版日期:2018-11-16 发布日期:2018-11-16

Fine-grained Disclosure Scheme for Attribute Certificate

  • Online:2018-11-16 Published:2018-11-16

摘要: 针对现有X. 509v4属性证书在细粒度出示部分属性后无法验证合法性的情况,提出了一种支持属性细粒度出示的证书方案。该方案由属性权威对证书中所有属性进行预处理,并对预处理结果生成签名;证书拥有者能够根据不同的应用场合移除证书中不相关属性,并计算验证证书必需的额外信息;验证方根据这些额外信息及证书中的签名能有效地验证被出示部分属性的合法性。该方案与现有标准兼容,并具有灵活性好、安全性高及付出额外开销小等特点。

关键词: 属性证书,细粒度,双重签名,隐秘特征属性,哈希树

Abstract: In order to effectively verify X. 509v4 attribute certificate after part of attributes is removed, a fine-grained disclosure scheme is proposed. In this scheme, every attribute in certificate is pretreated, and digital signature of the pretreated results was generated by attribute authority. In different scenarios,uncorrelated attributes is removed from certificate and essential validation information is calculated by certification owner. I}he validation information and digital signature in certificate can be used to validate legitimacy of the attributes disclosed. The scheme has some characteristics as follows : strong compatibility, good flexibility, high security and little additional cost

Key words: Attribute certificate, Fincgrained, Dual signature, Dark feature attribute, Hash tree

No related articles found!
Viewed
Full text


Abstract

Cited

  Shared   
  Discussed   
No Suggested Reading articles found!