提出了一种高效的基于身份的可用于多域的签密方案并引申出相应的数字签名方案,然后在该方案的基础上提出了一种适用于VoIP网络环境的安全机制,该机制避免了基于传统PKI的安全机制的诸多弊端,实现了跨域的身份认证与消息的机密传输。经过分析以及实现验证:该机制与已有的安全机制有很好的兼容性,且不降低原机制的安全性及有效性,同时解决了HTTP摘要认证下的单向认证以及预共享密钥问题,并消除了S/MIME基于证书认证和SRTP不提供密钥协商的不足。
An efficient identity-based signcryption scheme for multiple PKG environment and corresponding signature scheme were proposed, based on these, a security mechanism for VolP network was proposed. The mechanism overcorned some problems posed by traditional security mechanism based on PKI. Moreover, entity authentication for cross-domain and confidential transmission for message were supported in the security mechanism. Through validation and analysis, it is shown that the new is compliant well with security mechanism available in the primitive networks and does not affect its security and efficiency, and the deficiency in one-way authentication and pre-sharing key of HTTP di- gest authentication mechanism is resolved, the deficiency in certificate-based authentication of the S/MIME protocol and SRTP not providing key agreement function are eliminated.