为了对密钥协商协议实现匿名认证,进而有效保护通信方身份秘密,提出了一种基于可信平台模块(trusted platform module,TPM)的单向匿名认证密钥协商协议.该协议基于可信计算平台,引入TPM技术,不但实现了认证和密钥协商的安全属性要求,还满足了用户匿名的需求,使通信一方在不泄露其真实身份的前提下,向验证方证明其为某个群系统的合法成员,并在群管理员的配合下生成一个临时身份,提供了较好的安全性,适用于计算和存储资源有限的应用场合.
To implement the anonymous authentication with key agreement protocol and protection of the communicating parties identity secret effectively, a TPM based authentication key agreement protocol with one-way anonymous was proposed. The protocol was based on trusted computing platform, the introduction of TPM technology, not only had a range of key agreement protocol security properties, but also the communication party members without revealing the true identity of the premise to verify each other with some kind of membership, provided a more good security for the limited computing and storage resources applications.