论文部分内容阅读
针对云计算环境中服务资源跨域访问频繁,安全管理边界模糊,域外陌生资源的访问与调度需要进行身份验证和信任度量.在研究可信计算远程证明方法的基础上,提出一种采用环签名机制的消息签名算法和信任验证协议.利用域内可信资源的TPM公钥信息构建的环方程对消息进行签名与信任验证,提供无须第三方参与的验证双方可信证明.相比较常用的远程证明方法,这种方法具有计算效率高、证明过程便捷的特点,适合跨域云服务资源访问环境.通过构建安全模型证明了方法安全性,利用运算类型对比说明了方法高效性,在Hadoop平台下的应用实验验证了方法的可行性.
In view of the frequent cross-domain access of service resources in cloud computing environment, the ambiguous boundary of security management and the access and scheduling of unfamiliar resources outside the domain, authentication and trust measurement are required.On the basis of researching the remote computing method of trusted computing, Mechanism signature algorithm and trust verification protocol.Using the ring equation constructed by the TPM public key information of trusted resources in the domain to sign and trust the message and provide the trusted proof of both parties without the participation of the third party.Compared with the more common remote proof Method, which has the characteristics of high computational efficiency and provable process, and is suitable for cross-domain cloud service resource access environment.The security of the method is proved by constructing a security model, the efficiency of the method is illustrated by comparison of operation types, and under the Hadoop platform The experiment proved the feasibility of the method.