Anonymous authentication scheme for XML security standard with Refreshable Tokens

Anonymous authentication scheme for XML security standard with Refreshable Tokens
复制标题

可刷新令牌的 XML 安全标准匿名认证方案

DOI:
10.1145/968559.968573
复制
发表时间:
2003
期刊:
BRICS Report Series
影响因子:
--
通讯作者:
H. Imai
H. Imai
中科院分区:
--
文献类型:
--
作者:
R. Shigetomi;Akira Otsuka;H. Imai

文献摘要

被引文献

相似文献

匿名性是互联网交易中非常期望的特征。另一方面,无条件匿名可能包含一些陷阱。例如,它可能导致不负责任地使用互联网,甚至犯罪。因此,在我们的互联网应用中具有可验证的匿名性将是可取的。在这项工作中,我们提出了一个匿名认证方案的WS-Security。我们的方案保证了用户的匿名性,但服务器可以在不公开用户身份的情况下检查甚至拒绝用户访问特定服务的权利。我们用来实现可拒绝匿名协议的主要工具是“可刷新令牌”。我们的计划不需要任何积极的可信第三方在文献中以前的作品相比。然而,在需要怀疑恶意行为的用户的身份的情况下,服务器可以很容易地拒绝用户的服务。
Anonymity is a highly desired feature in Internet transactions. On the other hand, unconditional anonymity may contain some traps. For instance, it may cause irresponsible, or even criminal, use of the Internet. Thus, it would be desirable to have revocable anonymity in our internet applications. In this work, we suggest an anonymous authentication scheme for WS-Security. Our scheme assures the user's anonymity but the server can check, and even reject without unveiling the user's identification the user's right for accessing a specific service. The main tools which we use to achieve our rejectable anonymous protocols are "Refreshable Tokens". Our scheme does not require any active trusted third party in contrast to previous works in the literature. However, in situations where the identity of a user suspect of malicious act is required, the server could be easily to deny the user's service.