鉴于一个用户的身份在开放系统中不足以证明他是否可信,本文提出了一种基于属性的信任自动建立方法.交互的双方首先互相交换自己的信任书,信任书中包含了一些加密的敏感属性,然后根据自己的访问控制策略多次交换密钥,逐步向对方显示自己的敏感属性.该方法与传统的信任建立方法相比,具有存储空间小,计算量小以及抗攻击能力强等优点.
Because of the fact that user's identities are not enough to prove whether he is trusted or not, this paper presents a method to establish trust relationship automatically based on user's attributes. Credential which includes some encrypted attributes is exchanged firstly between strangers. And then two parties exchange secret key iteratively based on own access control policies to show sensitive attributes. It appears better performance such as small-storage-space, small-calculate-task and strong-resist attack than that of traditional trust establishment methods.