Journal of Information Security Reserach ›› 2024, Vol. 10 ›› Issue (2): 148-.

Previous Articles     Next Articles

Research on Identity Authentication Technology Based on Block Chain and PKI

Li  Mingkun1,2, Ma Limin1,2, Wang Jiahui3, and Zhang  Wei2   

  1. 1(Beijing Key Laboratory of Internet Culture and Digital Dissemination Research (Beijing Information Science & Technology University), Beijing 100101)
    2(School of Computer, Beijing Information Science & Technology University, Beijing 100101)
    3(Department of Information and Security, State Information Center, Beijing 100045)
  • Online:2024-02-21 Published:2024-02-22



  1. 1(网络文化与数字传播北京市重点实验室(北京信息科技大学)北京100101)
  • 通讯作者: 李铭堃 硕士.主要研究方向为网络数据安全、密码应用技术.
  • 作者简介:李铭堃 硕士.主要研究方向为网络数据安全、密码应用技术. 马利民 博士,副教授.主要研究方向为网络安全协议、信息隐藏技术、大数据安全. 王佳慧 博士,研究员.主要研究方向为云计算安全、大数据安全、云取证安全. 张伟 博士,教授.主要研究方向为大数据存储与安全、软硬件协同设计.

Abstract: Public key infrastructure (PKI) is a secure system based on asymmetric cryptographic algorithm and digital certificate to realize identity authentication and encrypted communication, operating on the principle of  trust transmission based on trust anchor. However, this technology has the following problems: The CA center is unique and there is a single point of failure; The authentication process involves a large number of operations, such as certificate resolution, signature verification, and certificate chain verification. To solve the above problems, this paper builds an identity authentication model based on Changan Chain, and proposes an identity authentication scheme based on Changan Chain digital certificate and public key infrastructure. Theoretical analysis and experimental data demonstrate  that this scheme reduces certificate parsing, signature verification and other operations, simplifies the authentication process, and improves the authentication efficiency.

Key words: chainmaker digital certificate, chainmaker, certificate parsing, digital signature, signature verification, identity authentication

摘要: PKI是基于非对称密码算法和数字证书来实现身份认证和加密通信的安全体系,原理是基于信任锚的信任传递.该技术存在以下问题:CA中心唯一,存在单点故障;认证过程存在大量证书解析、签名验签、证书链校验等操作,认证流程繁琐.针对上述问题,基于长安链构建身份认证模型,提出基于长安链数字证书和公钥基础设施的身份认证方案,理论分析和实验数据表明,该方案减少了证书解析、签名验签等操作,简化认证流程,提高了认证效率.

关键词: 长安链数字证书, 长安链, 证书解析, 数字签名, 签名值验证, 身份认证

CLC Number: