论文标题
用户管理的间接授权社会认证方法用于私人密钥恢复
An Owner-managed Indirect-Permission Social Authentication Method for Private Key Recovery
论文作者
论文摘要
在本文中,我们提出了一种非常安全和可靠的所有者管理的私钥恢复方法。近年来,公共密钥身份验证(PKA)方法已被确定为最可行的在线安全解决方案。但是,失去私钥还意味着失去与私钥相关的资产所有权的风险。为了保护关键,通常采用的某种解决方案需要一个新的秘密来保护目标秘密并陷入循环保护问题,因为新秘密也必须受到保护。为了解决循环保护问题并提供真正的安全和可靠的解决方案,我们建议将私钥的许可和拥有。然后,我们使用选定受托人的开放式公共钥匙创建许可的秘密股份,同时让所有者拥有权限加密的私钥。然后,通过应用社会身份验证方法,可以轻松检索恢复私钥的许可。我们的分析表明,我们提出的间接征收方法的六个数量级比
In this paper, we propose a very secure and reliable owner-self-managed private key recovery method. In recent years, Public Key Authentication (PKA) method has been identified as the most feasible online security solution. However, losing the private key also implies the risk of losing the ownership of the assets associated with the private key. For key protection, the commonly adopted something-you-x solutions require a new secret to protect the target secret and fall into a circular protection issue as the new secret has to be protected too. To resolve the circular protection issue and provide a truly secure and reliable solution, we propose separating the permission and possession of the private key. Then we create secret shares of the permission using the open public keys of selected trustees while having the owner possess the permission-encrypted private key. Then by applying the social authentication method, one may easily retrieve the permission to recover the private key. Our analysis shows that our proposed indirect-permission method is six orders of magnitude more secure and reliable than