透過您的圖書館登入
IP:3.15.171.202
  • 期刊
  • OpenAccess

分散式系統安全機制之設計

Design of a Security Mechanism for Distributed Systems

摘要


本文針對分散式系統提出新的安全機制。研究動機在於改善集中式安全機制的嚴重缺點。由於集中式安全被制容易受到入侵者的侵犯,在分散式系統引用集中式安全機制並不可行。本文提出之分散式系統安全機制主要包括二個部份:一是ADKG機制,目的在確保金匙產生過程的安全與正確:其次是DUA機制,用以確認使用者之身份與權利。此外,本文也提出植基於重寫規則的SSPRB產生器來製作金匙。為了安全考慮,本又利用多個安全管理中心共同產生使用者認證所需之票證,以為使用者要求服務的依據。研究結果顯示,本文有三項特點:SSPRB產生器是一種創新的作法,具有較低的計算成本與較大的種子空間;ADKG機制則提供精確而又安全的金匙產生程序;為了增強分散式系統之安全,DUA機制提供穩定可靠的使用者認證方式,以使得安全管理中心一旦遭受入侵,也不會危及整個系統的安全。

並列摘要


A security mechanism for distributed systems is proposed in this paper. The motivation is to improve the serious drawback of applying a centralized security mechanism. Application of a centralized security mechanism for distributed systems is not workable since it is vulnerable to the intruders. The proposed security mechanism for distributed systems consists of two major components. One is the ADKG (Automatic Double-checking Key Generation) mechanism applied to ensure the safety and correctness of the generated key; the other is the DUA (Distributed User Authentication) mechanism used to identify the privilege and individuality of the user. An SSPRB (Securely Strong Pseudo-Random Bit) generator is also used to generate the security keys for the ADKG mechanism. The SSPRB generator is designed on the basis of the rewriting rules. For safety consideration, multiple security sites are simultaneously operated to generate a ticket for an applicant, any request for services is then certified by that ticket. There are three characteristics in the proposed security meshanism. The first is the innovative SSPRB generator which offers advantages of lower computation burden and larger seed space. The second is that the ADKG mechanism presents a precise and secure scheme for the key generation procedure. The third is that the DUA mechanism provides a reliable and steady approach for user authenticaton. Any successful intrusion into a security site would not imperil the security of the entire system.

延伸閱讀