在网络信息安全领域,服务器与客户机之间的密钥协商显得非常必要。无证书公钥密码是为了克服基于身份密码的密钥托管性质提出来的,它结合了传统公钥证书密码体系和基于身份的公钥体系的优点。应用椭圆曲线的配对运算,提出了一个两方的无证书密钥协商协议,其中每一方只需计算一个配对,并证明了它在ECK模型下的安全性。与其他无证书密钥协商协议相比,安全性和效率都更好。
In the area of network information security, key agreement is essential between servers and clients. To overcome the key escrow property of identity-based cryptography, proposed certificateless public key cryptography, it combined the advantages of the traditional PKI and the identity-based cryptography. This paper proposed a new certificateless two-party key agreement protocol using pairing operation in elliptic curves, it only required each party to compute one pairing. Proved its security in ECK( extended Canetti-Krawezyk) model. Compared with existing eertifieateless protocols, the newly proposed key agreement protocol has better security and efficiency.