为了满足虚拟企业资源在异构域间的安全有效共享,提出一个基于访问授权票据的跨异构域认证及密钥协商方案。利用基于公钥认证机制的分布式信任模型,在公钥基础设施域的认证中心证书授权与Kerberos域的认证服务器之间建立起第一级信任关系;在此基础上,由认证中心(或认证服务器联合票据授予服务器)生成并分发外域用户U访问本域资源S的授权票据,并通过设计基于对称密钥密码体制的双向跨域认证及密钥协商协议,建立U与S之间的第二级信任关系,协议的安全性通过SVO逻辑得到证明。分析表明,在满足各级安全需求的前提下,所提方法有效降低了终端计算量与通信量,可完全避免Kerberos域终端的公钥加解密运算,在虚拟企业跨异构域身份认证过程中具有良好的可实施性。
To satisfy the safe and effective sharing of virtual enterprises in heterogeneous domain, a heterogeneous cross-domain authenticated key agreement scheme based on access authorization tickets was proposed. The first-tier trust relationship between Certificate Authority (CA) in PKI domain and Authentication Server (AS) in Kerberos domain by using public key crypto system-based distributed trust model was established. On this basis, the access authorization tickets generated by CA (or AS together with ticket granting service) was distributed to external do- main U to access internal domain S, and the second-tier trust relationship between U and S was built by designing two-way cross-domain authenticated key agreement protocol based on symmetry-key system. The security of the new scheme was proved by SVO logic. The analysis showed that the public key cryptographic operations could be entire- ly avoided for the end users or resources in Kerberos domains, which had better implementation in heterogeneous cross-domain identity authentication process.