Intersection-policy private mutual authentication from authorized private set intersection

Intersection-policy private mutual authentication from authorized private set intersection
复制标题

DOI:
10.1007/s11432-019-9907-x
复制
发表时间:
2020-01
期刊:
Science China Information Sciences
影响因子:
--
通讯作者:
Yamin Wen;Fangguo Zhang;Huaxiong Wang;Yinbin Miao;Zheng Gong
Yamin Wen;Fangguo Zhang;Huaxiong Wang;Yinbin Miao;Zheng Gong
中科院分区:
其他
文献类型:
--
作者:
Yamin Wen;Fangguo Zhang;Huaxiong Wang;Yinbin Miao;Zheng Gong

文献摘要

相似文献

私有相互身份验证(PMA)支持由同一可信组授权机构认证的两个用户之间的双向匿名身份验证。大多数现有的PMA方案集中在获取一个相对单一的认证策略,确保从属关系隐藏或指定的单属性匹配。然而,在实践中,通常向用户提供多个属性。除了从属关系隐藏的要求,如何有效地实现更灵活的多属性应用程序的认证策略仍然是一个具有挑战性的问题。当属性交集不是空集或其基数不小于阈值时,也需要用于认证的交集策略。针对上述问题,提出了一种基于身份加密的具有前向安全性的最优授权私有集交集协议,并设计了一种新的具有交集策略的PMA协议IP-PMA,该协议为来自同一组织的两个成员(拥有多个属性)之间的秘密握手提供了一种简单的解决方案.形式化的安全性分析证明了我们提出的两个协议在随机预言模型下是安全的。实验结果表明,IP-PMA协议具有线性复杂度优化,更适合于资源受限的应用。
Private mutual authentication (PMA) enables two-way anonymous authentication between two users certified by the same trusted group authority. Most existing PMA schemes focus on acquiring a relatively onefold authentication policy that ensures affiliation-hiding or designated single-attribute matching. However, in practice, users are typically provided with multiple attributes. In addition to the affiliation-hiding requirement, how to effectively achieve a more flexible authentication policy for multi-attribute applications remains a challenging issue. The intersection policy for authentication is also required when the attribute intersection is not an empty set or its cardinality is no less than a threshold value. To solve the above problems, we first propose an optimal authorized private set intersection protocol with forward security based on identity-based encryption and then design a new PMA protocol with intersection-policy called IP-PMA, which provides a simple solution for secret handshakes between two members (holding multiple attributes) from the same organization. Formal security analyses proved that our two proposed protocols are secure in the random oracle model. Empirical tests demonstrated that the IP-PMA protocol is optimized with linear complexity and may be more suitable for resource-constrained applications.