论文部分内容阅读
针对计算机系统和用户行为日志安全问题,提出日志身份戳、日志安全身份戳、前向安全的日志身份戳等概念,并利用基于身份的公钥加密体制(IBE)设计日志安全身份戳系统,实现对日志审计用户的身份追溯和满足前向安全的日志加密等功能.IBE加密体制无需PKI公钥证书,可灵活实现基于身份标识的加密和签名.首先在研究IBE加密体制的基础上,实现以密钥管理为中心的IBE应用系统;将IBE应用于日志身份戳的设计,提出了一个基于IBE的安全日志身份戳应用系统LogIDStamp,并分析了系统应用的安全问题;最后实现系统测试,与PKI日志加密作性能比较,体现了安全和性能优势.
In order to solve the security problems of computer system and user behavior log, the concepts of log identity, log security identity and forward-secure log identity are put forward, and the log identity authentication system is designed with identity-based public key cryptosystem (IBE) Trace the identity of log audit users and satisfy the function of forward-secure log encryption.IBE encryption system can realize identity-based encryption and signature flexibly without PKI public key certificate.Firstly, based on the research of IBE encryption system, Key management as the center of the IBE application system; the application of IBE to log identity stamp design, put forward a IBID-based security log identity stamp application system LogIDStamp, and analysis of the system application security issues; Finally, system testing, and PKI Log encryption for performance comparison, reflecting the safety and performance advantages.