针对应用互联网密钥交换(IKE)方法要对大量数据和高密度运算执行非对称密钥密码学操作而导致效率不高的问题,提出一种基于随机重用的身份认证密钥交换方法。首先分析云计算环境中云控制器的作用;然后设计该方法的三个独立组件;最后对其进行安全性分析。理论分析和实验结果均表明,相比IKE方案,该方法通过动态减少了时间消耗和计算负载,并且无需牺牲安全级别即可显著提高效率。
The Internet Key Exchange (IKE) scheme suffers from low efficiency because it performs asymmetric-key cryptological opera- tions over a large amount of data and high-density operations. For this issue, we proposed a random reuse-based authentication key exchange scheme. First, we analysed the role of cloud controller in cloud computing. Then, we designed three independent components of the scheme. Finally, we analysed the security of the scheme. Theoretical analyses and experimental results all demonstrated that compared with the IKE scheme, this one significantly improved the efficiency by dynamically reducing time consumption and computation load without sacrificing the level of security.