J4 ›› 2011, Vol. 38 ›› Issue (1): 176-183.doi: 10.3969/j.issn.1001-2400.2011.01.029

• 研究论文 • 上一篇    下一篇

一种用于移动通信的匿名认证方案

刘金业1;谷利泽1;罗守山1;杨义先1;崔军2;吴兴耀3   

  1. (1. 北京邮电大学 网络与交换技术国家重点实验室信息安全中心,北京  100876;
    2. 天津市国瑞数码安全系统有限公司 北京研发中心,北京  100088;
    3. 中国移动通信集团设计院有限公司,北京  100088)
  • 收稿日期:2009-11-22 出版日期:2011-02-20 发布日期:2011-04-08
  • 通讯作者: 刘金业
  • 作者简介:刘金业(1975-),男,北京邮电大学博士研究生,E-mail: liujinye18@sina.com.
  • 基金资助:

    国家863计划资助项目(2007AA01Z430);国家自然科学基金资助项目(60821001);国家重大科技专项资助项目(2009ZX03004-003-03)

Anonymous authentication scheme for mobile communication

LIU Jinye1;GU Lize1;LUO Shoushan1;YANG Yixian1;CUI Jun2;WU Xingyao3   

  1. (1. Info. Security Center, State Key Lab. of Networking and Switching Tech., Beijing Univ. of Posts and Telecommunications, Beijing  100876, China;
    2. National Cybernet Security Co., Ltd., Beijing  100088, China;
    3. China Mobile Group Design Inst. Co., Ltd., Beijing  100088, China)
  • Received:2009-11-22 Online:2011-02-20 Published:2011-04-08
  • Contact: LIU Jinye

摘要:

为了使移动网络向用户提供匿名服务,保证用户的身份和行踪等信息的机密性,提出了一种匿名认证方案,不仅解决了用户在漫游网中的匿名问题,而且也解决了在归属网中难以实现的匿名服务问题.本方案不仅通信量小,而且也无需每次更换密钥.本方案以知识证明为基础,采用直接匿名认证协议理论并结合加密传输和签名验证来实现.理论和分析实验表明,用户漫游时无需到家乡代理验证身份,且在归属网中无需映射出自己的真实身份,有效地实现了全网匿名.

关键词: 认证, 匿名, 移动计算, 隐私保护

Abstract:

In order to enable the mobile network to provide anonymity services and ensure the confidentiality of the user's identity, whereabouts and other information, we put up an anonymous authentication scheme, which solves the problem of user's anonymity not only in roaming network, but also in adscription network. The scheme has not only a small amount of communication, but also does not need to change the key every time. The scheme is based on the knowledge proof, and uses the direct anonymous attestation protocol theory together with encrypting transfer and signature validation for its implementation. Theoretical analysis and experimental results demonstrate that users do not need to go to the home agent to authenticate the user's identity in the roaming network, and that there is no need to map out its true identity in the adscription network. It implements user's anonymity in the whole network effectively.

Key words: authentication, anonymous, mobile computing, privacy protecting

Baidu
map