  1. 东北大学软件中心;
P2P authentication based on durable P2P storage technique

Wen, Tao (1); Zhang, Yong (1); Guo, Quan (1); Li, Ying-Qiu (1)   

  1. (1) Software Center, Northeastern University, Shenyang 110004, China
摘要: 分析了认证方式的安全性、易用性和代价,认为在P2P系统中引入基于密码的认证方式是必要的.利用持久存储技术、可信计算思想和虚拟系统思想,通过构造存储用户信息的分布式的用户数据库和用于认证的可信实体,解决基于密码的身份认证中的两个关键问题:用户的个人信息无法存储及缺乏客观可信的认证实体执行认证,实现基于密码的认证方式.理论分析和原型系统证明了方案的可行性.该方案对于完善P2P的认证方式是一次有益的尝试.

关键词: P2P认证, 基于密码的认证, P2P持久存储, 可信计算, 虚拟系统

Abstract: Analyzing the security, easy-to-use operation and cost of authentication, introducing the password-based authentication into a P2P system is regarded as necessary. With the durable P2P storage techniques and the ideas about reliable computation and virtual system taken into account to provide a decentralized database for storing users' information and reliable entity for authentication, the two key problems using durable techniques of password-based identity authentication can be solved, i.e., a user's individual information is unable to store and lack of objectively reliable entity for implementing the password-based authentication. The theoretical analysis and prototype both verify the feasibility of the way proposed for authentication, which is a try beneficial to the improvement of authentication.
