Pseudo trust: Zero-knowledge authentication in anonymous P2Ps

Pseudo trust: Zero-knowledge authentication in anonymous P2Ps
复制标题

伪信任:匿名 P2P 中的零知识身份验证

DOI:
10.1109/tpds.2008.15
复制
发表时间:
2008-10-01
影响因子:
5.3
通讯作者:
Ma, Jian
Ma, Jian
中科院分区:
计算机科学2区
文献类型:
--
作者:
Lu, Li;Han, Jinsong;Ma, Jian

文献摘要

被引文献

相似文献

点对点 (P2P) 系统中的大多数信任模型都是基于身份的,这意味着为了让一个点信任另一个点,它需要知道另一个点的身份。因此,信任和匿名之间存在固有的权衡。据我们所知,目前还没有 P2P 协议能够提供完全的相互匿名以及身份验证和信任管理。我们提出了一种称为伪信任(PT)的零知识身份验证方案,其中每个对等点不使用其真实身份,而是使用单向哈希函数生成不可伪造且可验证的假名。设计了一种基于零知识证明的新型身份验证方案,以便在不泄露任何敏感信息的情况下对对等方进行身份验证。在PT的帮助下,大多数现有的基于身份的信任管理方案都适用于相互匿名的P2P系统。我们分析 PT 的安全性和匿名性,并使用跟踪驱动的模拟和支持 PT 的 P2P 网络原型来评估其性能。我们设计的优势包括:1)不需要集中的受信任方或证书颁发机构(CA); 2)高扩展性和安全性; 3)低流量和密码处理开销; 4)抵抗中间人攻击。
Most trust models in Peer-to-Peer (P2P) systems are identity based, which means that in order for one peer to trust another, it needs to know the other peer's identity. Hence, there exists an inherent trade-off between trust and anonymity. To the best of our knowledge, there is currently no P2P protocol that provides complete mutual anonymity as well as authentication and trust management. We propose a zero-knowledge authentication scheme called Pseudo Trust (PT), where each peer, instead of using its real identity, generates an unforgeable and verifiable pseudonym using a one-way hash function. A novel authentication scheme based on Zero-Knowledge Proof is designed so that peers can be authenticated without leaking any sensitive information. With the help of PT, most existing identity-based trust management schemes become applicable in mutual anonymous P2P systems. We analyze the security and the anonymity in PT and evaluate its performance using trace-driven simulations and a prototype PT-enabled P2P network. The strengths of our design include the following: 1) no need for a centralized trusted party or Certificate Authority (CA); 2) high scalability and security; 3) low traffic and cryptography processing overheads; and 4) man-in-the-middle-attacks resistance.