首页|面向高频跨域访问的安全多方鉴权模型

面向高频跨域访问的安全多方鉴权模型

扫码查看
现有的跨域鉴权方法大多依赖身份提供者的去中心化机制来确保鉴权凭据的可靠性,但在鉴权服务层面仍存在中心化带来的安全保护不足的问题.为了解决高频跨域访问中的鉴权安全问题,提出了一种多方鉴权模型.在该模型中借鉴了分布式共识思想,通过安全实用的拜占庭容错机制,实现了鉴权节点间的多方通信和联合鉴权;同时,基于鉴权结果,能够实时定位并替换风险鉴权节点,重组鉴权网络,增强了系统的弹性.仿真实验测试了该模型的抗攻击能力和服务质量.实验结果表明,当风险鉴权节点占比不超过33%时,鉴权结果依然安全可靠;鉴权时间开销随着节点规模的扩展缓慢增加,在合理的节点规模下具备一定的实时性,适用于高频跨域场景.此外,网络重组机制可独立运行,且时间开销可控,系统的鲁棒性良好.
A Secure Multi-Party Authentication Model for High-Frequency Cross-Domain Access
Most of the existing cross-domain authentication methods rely on the decentralized mechanism of identity providers to ensure the reliability of authentication credentials,but there is still insufficient security protection caused by centralized authentication services.To solve the authentication security problem in high-frequency cross-domain access,a multi-party authentication model is proposed.This model draws on the idea of distributed consensus and realizes the multi-party communication and joint authentication among authentication nodes through the safe and practical Byzantine fault-tolerant mechanism.Meanwhile,based on the authentication results,it can locate and replace the risk authentication nodes in real time,reorganize the authentication network and enhance the flexibility of the system.Simulation experiments tested the attack resistance and service quality of the model.The results show that when the proportion of risk authentication nodes does not exceed 33% ,the authentication results are still safe and reliable;the authentication time overhead increases slowly with the expansion of node scale and has a certain degree of real-time performance under a reasonable node size,which is suitable for high-frequency cross-domain scenarios.In addition,the network reorganization mechanism can operate independently,the time overhead is controllable and the system robustness is good.

cross-origin accessmulti-party authenticationpractical byzantine fault tolerancecyber resilience

陈麓竹、郑儿、岳天一、贾召鹏

展开 >

中国电子信息产业集团有限公司第六研究所,北京 100083

北京邮电大学网络空间安全学院,北京 100876

中国电子信息产业集团有限公司,北京 100190

跨域访问 多方鉴权 实用拜占庭容错 网络弹性

2024

北京邮电大学学报
北京邮电大学

北京邮电大学学报

CSTPCD北大核心
影响因子:0.592
ISSN:1007-5321
年,卷(期):2024.47(5)