由于P2P系统的开放、匿名等特点,传统的访问控制和认证方法已无法在P2P系统中对信任协商进行有效的支持。本文利用信任协商机制和多信任域技术对P2P系统进行安全管理。针对信任凭证在信任协商过程中存在的安全隐患,通过属性的使用记录实现信任凭证中属性集的约减,并给出一种基于属性集的可信度评估方法。该方法减少了访问者属性信息的不必要暴露,提高了信任协商交互的可靠性和安全性。
The features of peer-to-peer systems, such as user anonymity and openness, result in that the traditional access control and authentication cannot effectively assist the trust negotiation in peer-to-peer systems. This paper considers the management of security in peer-to-peer system by means of trust negotiation and multi-domain technique. Aiming at the problem of the dangers hidden in credentials for trust negotiation, this paper proposes a method based on the attributes usage records to reduce the attributes sets in credentials. An evaluation method of the creditability is presented based on attributes sets. These methods reduce the possibility of unnecessary exposure of attributes and enhance the reliability and security in trust negotiation.