作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2006, Vol. 32 ›› Issue (18): 157-159. doi: 10.3969/j.issn.1000-3428.2006.18.057

• 安全技术 • 上一篇    下一篇

具有入侵容忍特性的身份认证系统

黄建华,程晓松,宋国新   

  1. (华东理工大学计算机系,上海 200237)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2006-09-20 发布日期:2006-09-20

Authentication System with Intrusion-tolerant Feature

HUANG Jianhua, CHENG Xiaosong, SONG Guoxing   

  1. (Department of Computer, East China University of Science and Technology, Shanghai 200237)
  • Received:1900-01-01 Revised:1900-01-01 Online:2006-09-20 Published:2006-09-20

摘要: 描述了一个具有入侵容忍特性的分布式身份认证系统,利用多代理和冗余共享验证服务器的设计,使得认证系统具有容忍入侵的能力。将用户密码数据分布存储在多个共享认证服务器中,使得少数服务器受到入侵时仍能继续提供认证服务并且不会暴露用户的密码信息,提高了认证系统的可用性及安全性。

关键词: 认证, 入侵容忍, 秘密共享, 代理

Abstract: This paper proposes a distributed authentication system with intrusion-tolerant feature. The authentication system is able to tolerate intrusions using the redundant proxy servers and shared authentication servers. With the method of distributing user’s key into several shared authentication servers, system continuously provides authentication services and not exposes user’s key even under intrusion. Through this scheme, the availability and security of authentication system are enhanced.

Key words: Authentication, Intrusion-tolerant, Secret sharing, Proxy