为了解决现有密钥分配协议所存在的工作效率偏低和资源占用率偏高等问题,提出了一种基于椭圆曲线密码体制的高效安全密钥分配协议.该协议通过引入公钥自证明思想,将用户身份认证和密钥数据恢复有机结合在一起,无需繁琐的身份鉴别认证操作和时钟同步过程,也无需可信CA中心和时戳服务器,只需要一次数据发送过程即可直接完成密钥分配任务.分析表明,该协议结构简单,具有较高的工作效率、较低的资源占用率和较强的安全性,能有效抵抗目前已知的各种攻击.
A new key distribution scheme based on the elliptic curve cryptc,system was developed to solve the lower efficiency and higher resource occupation problems of the existing key distribution schemes. The scheme combined the user identity authentication with key data recovery through inputting the idea of public key self-certified system and could finish the key distribution task in one data communication operation without the identity authentication operations, the time synchronization process, the trusted certification authority server, and the time stamp server. The analysis shows that the proposed scheme can resist the known attacks. It has simple structure, higher efficiency, lower resource occupation and stronger security.