【24h】

Authenticated Public Key Distribution Scheme Without Trusted Third Party

机译:没有可信第三方的经过身份验证的公钥分发方案

获取原文
获取原文并翻译 | 示例

摘要

Public key authentication is necessary to prevent a valid public key of a user from being compromised by a malicious user. Namely, if it is not provided, an adversary can read all encrypted messages between a sender and a receiver by substituting the public key of the receiver with her public key. In general, a certificate issued from and digitally signed by a publicly trusted certificate authority (CA) guarantees public key authentication under the assumption that all users can get the public key of the CA to verify the validity of certificates, i.e., the signatures of the CA. The assumption is practical and widely used in the real world. However, if the CA is down by a system faults or destroyed by a terror or a war, the assumption can not be preserved. In this paper, we propose a simple and practical scheme for public key authentication without any trusted third party. The scheme basically uses a message authentication code (MAC) taking a short random value as a key to authenticate the exchanged public keys. Our scheme also can be adopted in the environments such as ad-hoc or ubiquitous in which it is hard to settle a publicly trusted authority.
机译:为了防止恶意用户破坏用户的有效公共密钥,必须进行公共密钥身份验证。即,如果没有提供,则对手可以通过用接收者的公共密钥替换接收者的公共密钥来读取发送者和接收者之间的所有加密消息。通常,在所有用户都可以获取CA的公共密钥以验证证书有效性的假设下,由公共信任的证书颁发机构(CA)颁发并由其进行数字签名的证书可保证公共密钥身份验证。 CA。该假设是实用的,并且在现实世界中被广泛使用。但是,如果CA因系统故障而关闭或由于恐怖或战争而毁坏,则无法保留该假设。在本文中,我们提出了一种简单实用的公钥认证方案,无需任何可信任的第三方。该方案基本上使用以短随机值作为密钥的消息认证码(MAC)来认证交换的公共密钥。我们的方案还可以在难以解决公共信任的权威的临时或无所不在的环境中采用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号