基于格上身份认证密钥协商的 OPC UA 握手机制

OPC UA HANDSHAKE MECHANISM BASED ON IDENTITY-BASED AUTHENTICATED KEY AGREEMENT FROM LATTICE

  • 摘要: 由于量子计算技术的飞速发展,传统工业通信基础 OPC 统一架构(OPC UA)协议面临着严峻的潜在安全威胁。依据 OPC UA 的安全模型,设计一个基于格上身份认证密钥协商的 OPC UA 握手机制,安全性基于格上困难问题的难解性,可以抵抗量子计算攻击。密钥协商的过程中一个高效的格上身份加密方案所构造,没有使用开销大的公钥签名算法,实现了隐式认证。利用基于身份的密码机制,所提 OPC UA 方案还可以消除公钥证书,不再依赖复杂的公钥基础设施(PKI)。利用仿真实验验证了方案的可行性,通过性能分析从理论上证明了方案的安全性和执行效率。

     

    Abstract: Due to the rapid development of quantum computing technology, traditional industrial communication basic OPC unified architecture (OPC UA) protocol is facing a serious potential security threat. According to the security model of OPC UA, a OPC UA handshake mechanism based on identity-based authenticated key agreement from lattice is proposed, the security of the scheme is based on the intractability of hard problem on lattices, and can resist quantum computing attacks. The process of authenticated key agreement was constructed by an efficient identity encryption scheme on lattice, which attained implicit authentication without employing any public key signature algorithm with a high overhead. Due to using the identity-based cryptographic mechanism, the proposed OPC UA scheme eliminated the public key certificates and no longer relied on the complex public key infrastructure (PKI). The feasibility of the proposed scheme was verified by simulation experiments. The security and execution efficiency of the scheme were theoretically proved by performance analysis.

     

/

返回文章
返回