首页> 外文会议>International Conference on Security and Cryptography >Distributed Threshold Certificate based Encryption Scheme with No Trusted Dealer
【24h】

Distributed Threshold Certificate based Encryption Scheme with No Trusted Dealer

机译:基于分布式阈值证书的加密方案,没有可信经销商

获取原文

摘要

Generating certified keys and managing certification information in a fully distributed manner can find a wide range of applications in the increasingly distributed IT environment. However, the prohibition of trusted entities within the distributed system and the high complexity certificate management and revocation mechanism, hinder the adoption of this approach in a large scale. Threshold cryptography offers an elegant solution to these issues through Shamir's secret sharing scheme, where a secret (the Certificate Authority's (CA) master key) is split and shared among all participants. Combining this approach with the reasonable certificate service requirements of Certificate based encryption (CBE) schemes could result in a functional and efficient distributed security scheme. However, centralized entities, denoted as trusted dealers, are needed in most threshold cryptography schemes even those few that support CBE, while the static way in which the system's functionality is viewed, considerably limits possible applications (i.e. dynamic environments like p2p, Ad-Hoc networks, MANETS). In this paper, we explore the potentials of combining the latest developments in distributed key generation threshold cryptography schemes with efficient yet highly secure certificate based encryption schemes in order to provide a solution that matches the above concerns. We draft a fully distributed Threshold Certificate Based Encryption Scheme that has no need for any centralized entity at any point during its operating cycle, has few requirements concerning certificate management due to CBE and does not need any trusted dealer to create, and split secrets or distribute certificates. The proposed scheme has an easy participant addition-removal procedure to support dynamic environments.
机译:以完全分布的方式生成认证密钥和管理认证信息,可以在越来越多的IT环境中找到广泛的应用程序。但是,禁止分布式系统内的可信实体和高复杂性证书管理和撤销机制,妨碍以大规模采用这种方法。阈值加密术通过Shamir的秘密共享计划提供了这些问题的优雅解决方案,其中秘密(证书颁发机构(CA)Master Key)被分割并在所有参与者中共享。将这种方法与基于证书的加密(CBE)方案的合理证书服务要求相结合,可能导致功能性和有效的分布式安全方案。但是,在大多数支持CBE的大多数阈值密码方案中,需要集中的实体,表示为可信经销商,即使是那些支持CBE的那些,而是查看系统功能的静态方式,大大限制了可能的应用程序(即,P2P等动态环境,Ad-Hoc网络,舰队)。在本文中,我们探讨了与基于有效且高度安全的证书的加密方案相结合的分布式密钥生成阈值密码方案中的最新进展,以提供与上述问题匹配的解决方案。我们起草了一个完全分布式的阈值基于阈值的加密方案,无需在其操作周期中的任何点都不需要任何集中式实体,对由于CBE引起的证书管理有很少的要求,并且不需要任何可信经销商来创建和拆分秘密或分配证书。该方案具有易于参与者的附加删除过程,以支持动态环境。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号