信息安全研究 ›› 2024, Vol. 10 ›› Issue (2): 148-.

• 学术论文 • 上一篇    下一篇

基于区块链和PKI的身份认证技术研究

李铭堃1,2马利民1,2王佳慧3张伟2   

  1. 1(网络文化与数字传播北京市重点实验室(北京信息科技大学)北京100101)
    2(北京信息科技大学计算机学院北京100101)
    3(国家信息中心信息与网络安全部北京100045)
  • 出版日期:2024-02-21 发布日期:2024-02-22
  • 通讯作者: 李铭堃 硕士.主要研究方向为网络数据安全、密码应用技术. 15601127733@163.com
  • 作者简介:李铭堃 硕士.主要研究方向为网络数据安全、密码应用技术. 15601127733@163.com 马利民 博士,副教授.主要研究方向为网络安全协议、信息隐藏技术、大数据安全. markgoogle@qq.com 王佳慧 博士,研究员.主要研究方向为云计算安全、大数据安全、云取证安全. wangjiahui@sic.gov.cn 张伟 博士,教授.主要研究方向为大数据存储与安全、软硬件协同设计. zhwei@bistu.edu.cn

Research on Identity Authentication Technology Based on Block Chain and PKI

Li  Mingkun1,2, Ma Limin1,2, Wang Jiahui3, and Zhang  Wei2   

  1. 1(Beijing Key Laboratory of Internet Culture and Digital Dissemination Research (Beijing Information Science & Technology University), Beijing 100101)
    2(School of Computer, Beijing Information Science & Technology University, Beijing 100101)
    3(Department of Information and Security, State Information Center, Beijing 100045)
  • Online:2024-02-21 Published:2024-02-22

摘要: PKI是基于非对称密码算法和数字证书来实现身份认证和加密通信的安全体系,原理是基于信任锚的信任传递.该技术存在以下问题:CA中心唯一,存在单点故障;认证过程存在大量证书解析、签名验签、证书链校验等操作,认证流程繁琐.针对上述问题,基于长安链构建身份认证模型,提出基于长安链数字证书和公钥基础设施的身份认证方案,理论分析和实验数据表明,该方案减少了证书解析、签名验签等操作,简化认证流程,提高了认证效率.

关键词: 长安链数字证书, 长安链, 证书解析, 数字签名, 签名值验证, 身份认证

Abstract: Public key infrastructure (PKI) is a secure system based on asymmetric cryptographic algorithm and digital certificate to realize identity authentication and encrypted communication, operating on the principle of  trust transmission based on trust anchor. However, this technology has the following problems: The CA center is unique and there is a single point of failure; The authentication process involves a large number of operations, such as certificate resolution, signature verification, and certificate chain verification. To solve the above problems, this paper builds an identity authentication model based on Changan Chain, and proposes an identity authentication scheme based on Changan Chain digital certificate and public key infrastructure. Theoretical analysis and experimental data demonstrate  that this scheme reduces certificate parsing, signature verification and other operations, simplifies the authentication process, and improves the authentication efficiency.

Key words: chainmaker digital certificate, chainmaker, certificate parsing, digital signature, signature verification, identity authentication

中图分类号: