计算机科学 ›› 2012, Vol. 39 ›› Issue (8): 111-114.
• 计算机网络与信息安全 • 上一篇 下一篇
莫家庆,胡忠望,林瑜华
出版日期:
发布日期:
Online:
Published:
摘要: 针对目前可信计算平台直接匿名认证(DAA)机制的不足,提出一种改进的匿名认证方案。该方案先采用 CA验证示证者的EK证书,协助示证者和DAA颁布者各自生成会话密胡,使DAA颁布者能够为示证者颁发秘密的 DAA证书;然后示证者用两承诺值相等协议及CF7证明协议来证明承诺值位于某个特定区间的方法,向验证者证明 其平台的真实合法性。分析表明,该方案具有较高的安全性,还具备不可欺骗性、匿名性、撤消性,效率更高。
关键词: 直接匿名认证,可信计算,零知识证明,网络安全
Abstract: An improved scheme was proposed against the shortage of current mechanism of direct anonymous attesta- tion(DAA) in trusted computing platform. This scheme firstly adopted the CA to verify the EK certificate of prover to help prover and DAA issuer building the session key respectively. The DAA issuer can issue the secret certificate to the prover with the key. hhen the prover used a committed number lying in a specific interval to attest the validity to the verifier by integrating the protocol that two committed numbers arc equal with the protocol of the CI}T proof. The anal sis shows that this scheme not only has a higher security, but also is non-fraudulence, anonymity, can be withdrawed and more efficiency.
Key words: Direct anonymous attestation, Trusted computing, Zero-knowledge proof , Network security
莫家庆,胡忠望,林瑜华. 基于特定区间承诺值证明机制改进的DAA认证方案[J]. 计算机科学, 2012, 39(8): 111-114. https://doi.org/
0 / / 推荐
导出引用管理器 EndNote|Reference Manager|ProCite|BibTeX|RefWorks
链接本文: https://www.jsjkx.com/CN/
https://www.jsjkx.com/CN/Y2012/V39/I8/111
Cited