首页> 外文会议>International Computer Science and Engineering Conference >RDI: Real Digital Identity Based on Decentralized PKI
【24h】

RDI: Real Digital Identity Based on Decentralized PKI

机译:RDI:基于分散式PKI的真实数字身份

获取原文

摘要

Establishing a digital identity plays a vital part in the digital era. It is crucial to authenticate and identify the users in order to perform online transactions securely. For example, internet banking applications normally require a user to present a digital identity, e.g., username and password, to allow users to perform online transactions. However, the username-password approach has several downsides, e.g., susceptible to the brute-force attack. Public key binding using Certificate Authority (CA) is another common alternative to provide digital identity. Yet, the public key approach has a serious drawback: all CAs in the browser/OS' CA list are treated equally, and consequently, all trusts on the certificates could be invalidated by compromising only a single root CA's private key. We propose a Real Digital Identity based approach, or RDI, on decentralized PKI scheme. The core idea relies on a combination of well-known parties (e.g., a bank, a government agency) to certify the identity, instead of relying on a single CA. These parties, collectively known as Trusted Source Certificate Authorities (TSCA), formed a network of CAs. The generated certificates are stored in the blockchain controlled by smart contract. RDI creates a digital identity that can be trusted based on the TSCAs' challenge/response and it is also robust against a single point of trust attack on traditional CAs.
机译:建立数字身份在数字时代起着至关重要的作用。认证和标识用户以安全地执行在线交易至关重要。例如,互联网银行应用程序通常要求用户提供数字身份,例如用户名和密码,以允许用户执行在线交易。然而,用户名-密码方法具有多个缺点,例如,容易受到蛮力攻击。使用证书颁发机构(CA)的公钥绑定是提供数字身份的另一种常见选择。但是,公钥方法有一个严重的缺点:浏览器/操作系统的CA列表中的所有CA都受到同等对待,因此,仅通过破坏单个根CA的私钥就可以使证书上的所有信任失效。我们提出了一种基于真实数字身份的方法,即分布式PKI方案的RDI。核心思想依靠知名方(例如,银行,政府机构)的组合来证明身份,而不是依赖单个CA。这些各方(统称为受信任源证书颁发机构(TSCA))形成了一个CA网络。生成的证书存储在智能合约控制的区块链中。 RDI基于TSCA的质询/响应创建了一个可以信任的数字身份,它还可以抵抗传统CA上的单点信任攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号