作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2012, Vol. 38 ›› Issue (01): 135-136. doi: 10.3969/j.issn.1000-3428.2012.01.041

• 安全技术 • 上一篇    下一篇

支持授权撤销的代理签名分析与改进

原变青1,张 忠2   

  1. (1. 山东广播电视大学计算机与通信学院,济南 250014;2. 山东大学计算机科学与技术学院,济南 250061)
  • 收稿日期:2011-06-30 出版日期:2012-01-05 发布日期:2012-01-05
  • 作者简介:原变青(1980-),女,讲师、硕士,主研方向:密码学,信息安全;张 忠,博士

Analysis and Improvement of Proxy Signature Supporting Authorization Revocation

YUAN Bian-qing 1, ZHANG Zhong 2   

  1. (1. College of Computer & Communications, Shandong TV University, Jinan 250014, China; 2. School of Computer Science & Technology, Shandong University, Jinan 250061, China)
  • Received:2011-06-30 Online:2012-01-05 Published:2012-01-05

摘要: 在基于时间戳撤销机制的代理签名方案中,授权服务器(AS)签发的时间戳内并不包含原始签名人的授权信息,使攻击者可以利用该缺陷绕过AS检查,获得合法的时间戳签名。为此,对AS生成时间戳阶段进行改进,使攻击者无法获得能够通过验证的时间戳签名,从而弥补原方案的安全缺陷。

关键词: 代理签名, 撤销, 时间戳, 原始签名者, 代理签名者

Abstract: According to in-depth security analyzing of a proxy signature scheme with revocation by the use of timestamp, it points out that the malicious proxy signer can obtain a valid timestamp whatever the original signer revoked the delegation or not because the time-stamp issued by Authentication Sserver(AS) do not bind with the delegation of original signer. Pointing at the problems existed in the timestamp generation phase, this paper proposes a more efficient scheme with fast revocation, which solves the weaknesses of original scheme fundamentally.

Key words: proxy signature, revocation, timestamp, original signer, proxy signer

中图分类号: