首页> 外文期刊>International Journal of Information Security >AAnA: Anonymous authentication and authorization based on short traceable signatures
【24h】

AAnA: Anonymous authentication and authorization based on short traceable signatures

机译:AAnA:基于简短可追踪签名的匿名身份验证和授权

获取原文
获取原文并翻译 | 示例
           

摘要

Due to the privacy concerns prevailing in today's computing environments, users are more likely to require anonymity or at least pseudonyms; on the other hand, they must be traceable or revokable in case of abuse. Meanwhile, an authorization mechanism that controls access rights of users to services or resources is frequently needed in various real-world applications but does not favor anonymity. To cope with these problems, we explore an anonymous authentication and authorization method that very efficiently supports fine-grained authorization services without losing strong but traceable anonymity. The efficiency of our method comes from atomizing authorization within a group and issuing multiple authorization values for a group membership. The cryptographic basis of our method is the famous short traceable signature scheme. Our method allows a user to selectively disclose authorization according to need and also provides revocation and update of authorization without revoking membership or anonymity. To prevent users from forging authorization, our method enables the users to prove their authorizations while hiding the corresponding authorization values from other users. We formally analyze security and compare the related methods in terms of efficiency and functionality.We show that our method is secure against misidentification, anonymity-break and framing attacks and is efficient within a reasonable bound while still providing various functionalities such as fine-grained authorization and authorization revocation, commonly required in many practical applications.
机译:由于当今计算环境中普遍存在的隐私问题,用户更可能要求匿名或至少使用假名。另一方面,一旦被滥用,它们必须是可追溯的或可撤销的。同时,在各种现实应用中经常需要一种控制用户对服务或资源的访问权限的授权机制,但是这种机制不支持匿名性。为了解决这些问题,我们探索了一种匿名身份验证和授权方法,该方法非常有效地支持细粒度的授权服务,而又不会失去强大但可追溯的匿名性。我们的方法的效率来自于在组内雾化授权并为组成员资格颁发多个授权值。我们方法的密码基础是著名的短可追溯签名方案。我们的方法允许用户根据需要有选择地公开授权,还可以撤销和更新授权,而无需撤销成员资格或匿名性。为了防止用户伪造授权,我们的方法使用户能够证明自己的授权,同时向其他用户隐藏相应的授权值。我们对安全性进行了正式分析,并在效率和功能方面对相关方法进行了比较,表明我们的方法在防止误识别,匿名破坏和成帧攻击方面是安全的,并且在合理范围内是有效的,同时仍提供各种功能,例如细粒度的授权和授权撤销,这在许多实际应用中通常是必需的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号