针对虚拟企业的敏捷、动态、低成本、组织模式多样等特点利用无可信中心椭圆曲线门限签名和可变多方协议提出一个基于虚拟桥CA的高效的广义虚拟企业跨域认证方案。方案借助虚拟桥CA的分布式创建和运行提供了灵活的跨域认证策略并避免实体桥CA的维护成本,可适应虚拟企业不同的组织模式及其动态变化,具备比特安全性高、计算量和通信量小、信任链短、抗合谋攻击等优点,能更好的满足虚拟企业盟员间(特别是终端计算资源或通信带宽受限情况下)的跨域认证需求。
In order to meet the special requirements of virtual enterprises (VE) ,this paper proposed an efficient generalized inter-enterprise authentication scheme .The scheme employed the elliptic curve threshold signature algorithm and the variable multi-party protocols to realize efficient cross certifications between VE partners through a virtual bridge CA .Analysis shows that the pro-posed scheme can provide a flexible distributed trust policy for VE ,and has the advantages of low computation and communication cost ,high bit-security ,short certificate-chains ,and adaptability to various structures of VE ,so it can better satisfy the special require-ments of inter-enterprise authentication in VE ,especially when the computation and communication resource is constrained .