基于SM9的OpenStack双向认证方案研究与设计  被引量:3

Research and Design of OpenStack Mutual Authentication Scheme Based on SM9

在线阅读下载全文

作  者:张柁苧 王雄[1] 池亚平[1] ZHANG Tuoning;WANG Xiong;CHI Yaping(Beijing Electronic Science and Technology Institute,Beijing 100070,P.R.China)

机构地区:[1]北京电子科技学院,北京市100070

出  处:《北京电子科技学院学报》2021年第4期45-50,共6页Journal of Beijing Electronic Science And Technology Institute

基  金:国家重点研发计划项目(2018YFB1004100)。

摘  要:OpenStack作为主流的开源云平台,其安全认证基于Keystone组件提供的UUID Token、PKI Token等方式,在总结分析OpenStack云平台目前基于Token认证的安全问题基础上,设计一种基于SM9的双向身份认证方案,利用SM9根据身份标识产生私钥的优点,解决了UUID Token无法本地认证、PKI Token证书管理复杂等问题,并在认证流程中完成SM9的安全密钥分发。经分析,该方案不仅简化了认证流程,同时也增强了Token的安全性。OpenStack is a prevailing open source cloud platform, whose security authentication is based on the UUID token and the PKI token provided by the keystone component. With a summary and analysis of the current security issues of token authentication based OpenStack cloud platform, in this paper, a mutual identity authentication scheme based on the SM9 is designed. In the scheme, the advantage of SM9 that the private key is generated according to the identity label is utilized to solve the problems that the UUID token lacks the capability of being authenticated locally and managing the PKI token certificate is complex. Meanwhile, SM9 security key distribution is completed in the authentication process. Analysis indicates that the scheme simplifies the authentication process and enhances the security of the token.

关 键 词:SM9算法 身份认证 OPENSTACK 

分 类 号:TN309[电子电信—物理电子学]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象