现有IBE的密钥管理机制存在许多问题和不足,例如用户私钥的安全分发问题(缺少一个安全的、定时的、自动的密钥更换机制)以及如何保证数据报的保密性、完整性、不可伪造性和不可否认性等问题.文中针对以上问题,提出一种改进的密钥管理方案,即密钥管理机制.它能够定时更换域内密钥并且安全分发,同时使用安全服务来保障数据报的保密性、完整性、不可伪造性和不可否认性.数据报的安全服务包括双重数字签名、数字信封以及数字时间戳.最后文章使用随机预言模型RO(Random Oracle)对文中提出的相关协议给出了安全性证明.
There still exist several problems in the prototype of IBE proposed by Boneh and Franklin, such as how to distribute private keys safely, the lack of a secure timing key replaced management mechanism and how to ensure message security of privacy, integrity and non-forgeability. Upon these above, a new scheme of the improved key management mechanism of IBE has been put forward, which is named as the trustworthy key management mechanism of IBE system. And it can change users' private keys regularly in this domain, which are subsequently distributed safely. Meanwhile it can also guarantee message security of privacy, integrity and non-forgeability by security service, which mainly includes Double Digital Signature, Digital Envelope and Digital Time-stamping. Finally, the proposed network protocols are proved to be secure by RO (Random Oracle) model.