给出一种新的兼顾隐私保护的角色认证方法.该方法认证具有普遍意义的主体角色,既满足认证需求又保护用户身份隐私,还方便对主体进行角色授权.方法内嵌的用户身份标识具有随机性和唯一性,能唯一地确定角色拥有者.服务方不能统计或链接该标识以推测用户行为或揭露用户真实身份.对方法的相关分析表明,该方法兼顾认证及隐私需求,且实现流程简易,计算效率高,便于应用部署.
Proposed a new way of Role-based authentication.This approach,through the use of a credential which holds the role of user's,can not only meet the requirement of verification of user but protect the user's privacy of identity.In the approach,one random and unique,short-lived identifier is embedded into the credential,and this identifier can not be tracked or linked to disclose the user's identity,meanwhile by using it services can differentiate each user.Relevant analysis presents the approach is secure,easy to deploy,and also has a close tie with role-based authorization.