An Identity Management and Authentication Scheme Based on Redactable Blockchain for Mobile Networks

An Identity Management and Authentication Scheme Based on Redactable Blockchain for Mobile Networks
复制标题

DOI:
10.1109/tvt.2020.2986041
复制
发表时间:
2020-06-01
影响因子:
6.8
通讯作者:
Hong, Peilin
Hong, Peilin
中科院分区:
计算机科学2区
文献类型:
--
作者:
Xu, Jie;Xue, Kaiping;Hong, Peilin

文献摘要

被引文献

相似文献

越来越多的用户渴望在不泄露隐私信息的情况下获得更全面的网络服务。传统上,为了访问网络,用户被授权具有身份和对应的密钥,其由网络运营商生成和管理。所有用户的个人识别信息由网络运营商集中存储。然而,这种方法使用户失去了对他们的个人识别信息的控制。用户担心谁可以访问这些敏感数据,以及这些数据是否已被泄露。在本文中,我们提出了一个基于区块链的身份管理和认证方案的移动的网络,其中用户的身份信息由用户自己控制。我们的方案让用户生成他们的自我主权身份(SSI)和相应的公钥和私钥。用于验证用户身份信息的私钥仅为用户所知。我们使用区块链记录合法用户的SSIs和公钥,并采用变色龙哈希来删除区块链上非法用户的信息,同时保持区块头不变。此外,其他服务提供商可以获取用户的SSI和公钥,并通过查询区块链来验证用户。实验结果表明,该方案可以大大降低撤销开销和通信开销。
More and more users are eager to obtain more comprehensive network services without revealing their private information. Traditionally, in order to access a network, a user is authorized with an identity and corresponding keys, which are generated and managed by the network operator. All users' personally identifying information are centralized stored by the network operator. However, this approach makes users lose the control of their personally identifying information. Users are concerned about who can access these sensitive data and whether they have been compromised. In this paper, we propose a blockchain-based identity management and authentication scheme for mobile networks, where users' identifying information are controlled by the users themselves. Our scheme let users generate their self-sovereign identities (SSIs) and corresponding public keys and private keys. The private key used to authenticate the user's identifying information is only known to the user. We use blockchain to record SSIs and public keys of legitimate user, and adopt chameleon hash to delete illegal users' information on the blockchain, while keeping the block head unchanged. Furthermore, other service providers can obtain the user's SSI and public key and authenticate users by querying the blockchain. Experimental results confirm that our scheme can greatly reduce the revocation overhead and communication overhead.