实用的多方不可否认协议必须具备存活性、公平性、时限性、无排斥性和保密性.文中指出现有典型协议,如KM,OZCL和OZL均无法提供时限性和无排斥性,而且易遭受服务失效等攻击,致使它们不能成为实用的协议.为此,给出一个新协议NKM,其基于无需全局时钟同步机制支持的时间段概念实现时限性,借助双重群加密技术确保具备保密性的同时不丢失无排斥性,利用证据链技术既可高效维护协议证据,又能避开服务失效和重放攻击;同时还形式化验证了该协议的安全性,并对协议部署时将牵涉到的安全问题进行了考虑.与现有协议相比,NKM在安全性和性能方面均存在优势,可成为实用的协议.
Practical multi-party non-repudiation protocols must respect viability, fairness, timeli ness, exclusion-freeness and confidentiality. In this paper, the authors point out that most of the existing representative multi-party non-repudiation protocols with online trusted third party, such as KM and its extensional version OZCL and OZL, lack the supports for the properties of timeliness and exclusion-freeness, and are vulnerable to denial of the non-repudiation service attack and so on. Bearing these issues in mind, the authors present a new protocol NKM, which respects timeliness with time-span notion, which does not need any global clock synchronism mechanism, and respects exclusion-freeness and confidentiality with double group encryption notion, and makes evidence managed efficiently and avoids potential denial of non-repudiation service attack and replay attack with evidence chain notion. Subsequently, the authors give a formal analysis of its security and put some consideration on some security issues of protocol deployment. Compared with existing protocols, NKM have advantage over them in terms of security and performance and can be a practical protocol.