计算机科学
公钥基础设施
梅克尔树
公钥密码术
认证(法律)
计算机网络
计算机安全
正确性
散列函数
加密
身份验证协议
领域(数学分析)
密码哈希函数
数学分析
数学
程序设计语言
作者
Jing Chen,Zeyi Zhan,Kun He,Ruiying Du,Donghui Wang,Fei Liu
出处
期刊:IEEE Transactions on Dependable and Secure Computing
[Institute of Electrical and Electronics Engineers]
日期:2021-06-28
卷期号:19 (5): 3301-3311
被引量:31
标识
DOI:10.1109/tdsc.2021.3092375
摘要
It is well known that each Public Key Infrastructure (PKI) system forms a closed security domain and only recognizes certificates in its own domain (such as medical systems, financial systems, and 5G networks). When users need to access services in other domains, their identities often cannot be recognized or PKI systems require extremely complex operations to authenticate the users’ identities. This is the cross-domain authentication problem. The distributed consensus feature of blockchain provides a technical approach to solve this problem. However, there are some unresolved problems in existing blockchain-based schemes. On one hand, due to the low throughput of blockchain systems, the response speed may be insufferable when the number of cross-domain authentication requirements becomes enormous. On the other hand, these schemes insufficiently consider the privacy risk in the cross-domain scenario. In this article, we propose an efficient privacy-preserving cross-domain authentication scheme called XAuth that is integrated naturally with the existing PKI and Certificate Transparency (CT) systems. Specifically, we design a lightweight correctness verification protocol based on Multiple Merkle Hash Tree for rapid response. To protect users’ privacy, we present an anonymous authentication protocol for cross-domain authentication. The security analysis and experimental results demonstrate that XAuth is secure and efficient.
科研通智能强力驱动
Strongly Powered by AbleSci AI