给出了用于基于移动代理(Agent)的服务复合的安全方案。该方案以双线性对为基础,利用有隙Diffie-Hellman问题的难解性,构造了一个新的数字签名方案,在进行数字签名时不要求移动Agent携带签名密钥,避免签名密钥被窃取。此外,该方案也保证了移动Agent所携带的服务操作参数信息的完整性。同时因其基于身份的特点,在验证Agent生成的签名和Agent的数据完整性时不需要与认证中心或密钥分发中心进行通信。
An identity-based security scheme with provable security was proposed for composition of services based on mobile agents. The scheme was constructed on bilinear pairings and the security of digital signature in this scheme relied on the difficulty of solving Gap Diffle-Hellman problems. In this scheme, there was no requirement for mobile agent to carry the private key when they generated digital signatures on behalf of the original service so that the private key would not he compromised. In addition, the integrity of service parameter information with mobile agent was also protected by this scheme. At the same time, the verification of signatures generated by mobile agents and the integrity of service parameters need not to communicate with Certificate Authority(CA) or Key Distribution Center(KDC) because the scheme was identity-based.