项目名称: 云身份管理及认证授权服务技术研究
项目编号: No.61472409
项目类型: 面上项目
立项/批准年度: 2015
项目学科: 自动化技术、计算机技术
项目作者: 张立武
作者单位: 中国科学院软件研究所
项目金额: 83万元
中文摘要: 随着云计算的发展,云身份管理及认证授权服务成为技术发展趋势,它有很多矛盾问题需要解决:支持超大规模用户和用户个性、需高安全认证授权和高性能处理、网络实名身份管理同时保护个人隐私,用户不信任公有云服务却需要把访问控制交给云决策,需要出示足够多属性访问应用却不能泄露不必要的用户属性。本项目拟提出支持国产密码算法SM2的百万次/秒云认证架构、亿次/秒的云访问控制,解决海量用户的认证授权请求处理问题,研究支持属性认证、匿名认证等技术实现多样化的用户需求;针对实名管理与用户隐私矛盾,提出多级云身份管理服务框架与技术;针对云访问控制服务的信任问题,利用公开云环境下的可验证计算模型、可信计算技术等技术,解决访问控制执行端对云服务的决策结果验证问题;研究门限SM2算法签名方案,解决应用中分享权限问题。项目拟形成ISO/IEC标准贡献3项,国家标准2项,行业标准2项,专利8项,实用云认证授权系统1套。
中文关键词: 云计算安全;安全协议;安全体系结构;访问控制;隐私保护
英文摘要: With the development of cloud computing, cloud identity management and authentication and authorization services become technology trends , it has many problems to solve contradictions : support for ultra- large-scale users and preserve user's personality,need high security authentication and authorization with high-performance processing , real name identity management and privacy protection, users do not trust public cloud services but hands the access function to the cloud , need to present enough attributes to access the application but don't leak unnecessary attributes. In the project, we intends to put forward million times / sec cloud authentication architecture of the domestic cryptographic algorithms SM2 , billion / sec Cloud Access control , put forward attribute based authentication and anonymous authentication technology to satisfy the diverse user needs ; propose a multi-level framework for cloud identity management services to solve the contradiction of real name management and privacy protection; trust issues for cloud services access control , utilize verifiable computation and trusted computing technology to resolve the problem that access execution point can verify the decision result from the cloud services; we also research SM2 threshold signature scheme algorithm to solve the application sharing permissions problem. This project is intended to make 3 ISO / IEC standards contributions , 2 national standards , 2 industry standards , 8 patents and 1 cloud authentication and authorization system.
英文关键词: Cloud Computing Security;Security Protocol;Security Architecture;Access Control;Privacy Protection