为解决电子政务系统的安全问题,分析了该系统采用公钥基础设施(public key infrastructure,PKI)和基于身份加密(identify-based encryptionI,BE)机制存在的不足,提出了基于分层的身份加密(hierarchical IBE,HIBE)机制的电子政务系统安全解决方案。该方案以HIBE为核心,利用表示用户身份的任意字符串为公钥、严格验证用户身份、椭圆曲线困难问题加密和设置分层密钥服务器等方法,保证了数据传输和存储过程中的保密性、完整性、可用性和不可抵赖性,有效克服了采用PKI和IBE机制存在的部署成本高、身份验证复杂、密钥托管和效率低下等缺点。理论及实验分析结果表明,该方案较好地解决了电子政务系统的安全性问题,具有良好的应用前景。
The mechanism of public key infrastructure(PKI) and identity-based encryption(IBE) is analyzed to solve the safety problems of E-government system,and a safety solution based on hierarchical IBE(HIBE) is proposed for E-government system.With HIBE as its core,this solution utilizes such methods as: any string of the user identity as public key;strict verification of user identity;elliptic curve encryption;and setting up hierarchical key server,etc.to ensure the confidentiality,integrity,serviceability,and non-repudiation during data transmission and storage.This effectively deals with such problems as high deployment cost,complicated identity verification,key escrow and low efficiency of PKI and IBE mechanism.The theoretical and experimental analyses indicate that the safety problems of E-government system is better solved and this mothod has promising application prospect.