为了实现电子文档安全管理环境中域间用户的通信安全,采用双线性对构造了一个适用于大数量、动态域组的基于身份的域密钥分发算法,该算法实现了域环境下用户的动态加入与离开,通过广播加密的方式使域用户获得更新后的域密钥,避免了复杂的密钥更新协商协议。另外,提出基于共享域的电子文档管理协议,实现域内用户共享,不同域之间安全分发电子文档。在该协议工作下,共享域内每个用户合法获得的电子文档可以在域中各设备间无缝地流动,实现资源共享。不同的域之间电子文档的传输有严格的限制,需要经服务器认证,确保电了文档的安全管理与防泄密。
In order to create a security domain environment in the E-document management, an identity domain key distribution scheme using bilinear pairings for large and dynamic domain was proposed. The scheme could handle the joining and leaving of domain members efficiently, and updateed the domain key in the manner of broadcast, which avoided the complex protocols of key agreement. In addition, the distribution protocol based sharing-domain for E-document was also given, which aimed to realize the function of sharing the documents in a domain and distributing the documents between different domains securely. With the protocol, the E-documents obtained by a domain member could be transmitted to other domain members seamlessly. On the opposite, the E-document which was distributed to another domain need to be upload to the server, which would verify the identity of the domain member and encrypt the documents with the specified domain key.