首页> 外文会议>International Conference on Computational Intelligence and Security >Combining User Authentication with Role-Based Authorazition Based on Identity-Based Signature
【24h】

Combining User Authentication with Role-Based Authorazition Based on Identity-Based Signature

机译:基于基于Identity的签名基于基于角色的授权组合用户身份验证

获取原文

摘要

Authentication and authorization are crucial for ensuring the security of information systems. Role-based access control (RBAC) can act as an efficient method of managing authorization of system resources. In this paper, we apply identity-based signature (IBS) technique to cryp-tographically provide user authentication and role-based authorization. To achieve this, we first extend the RBAC model to incorporate identity-based cryptography. Our access control architecture is derived from an identity-based signature scheme on bilinear pairings and eliminates the use of digital certificates. In our suggestion, the manager checks the validity of a user's identity and user's activated roles simultaneously by verifying a corresponding signature, thus the user authentication and role-based authorization procedures can be combined into one operation. We also prove the security of the proposed scheme in the random oracle model.
机译:身份验证和授权对于确保信息系统的安全性至关重要。基于角色的访问控制(RBAC)可以作为管理系统资源授权的有效方法。在本文中,我们将基于身份的签名(IBS)技术应用于CRYP-Tographical上提供用户身份验证和基于角色的授权。为此,我们首先扩展RBAC模型以包含基于身份的密码学。我们的访问控制架构是从Bilinear配对上的基于身份的签名方案派生的,并消除了数字证书的使用。在我们的建议中,经理通过验证相应的签名来检查用户身份和用户的激活角色的有效性,从而可以将用户认证和基于角色的授权过程组合成一个操作。我们还证明了随机oracle模型中提出的方案的安全性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号