为了解决P2P语音网络中节点认证和密钥协商问题,提出了一种基于身份签名的节点双向认证及密钥协商方法.首先从可信节点群中获得签名密钥碎片,并将其组合成节点的签名密钥,然后通过通信双方安全交互来完成相互认证.结合基于身份签名的Oakley密钥协商协议实现了通信双方的会话密钥协商.提出的基于身份签名的P2P语音认证及密钥协商方法均被证明是安全的.由于减少了系统认证过程中证书的传递以及对单个可信中心的依赖,极大地降低了基于身份签名的P2P语音认证及密钥协商方法的协议复杂度,可适用于分布式P2P语音安全通信系统中的不同处理平台.
To solve the difficult problems of node authentication and key agreement in P2P(peer-to-peer) network,a new scheme based on identity signature is proposed.Firstly a node gets signature key's scrap from the trusted nodes group,and then makes them into an integrated signature key,which is used to realize the mutual authentication of the communicating nodes effectively.Collaborated with the Oakley key agreement protocol,the proposed scheme can realize the conversation key agreement between the communicating nodes.The securities of the proposed scheme have been proved.Since the proposed scheme based on identity signature has reduced the times of certificate transmissions between authenticating nodes and has less relied on the authentication center,its computing complexity is low.It is fit for different computing platforms in P2P voice secure communication system.