SUN Haipeng, TAN Yu-an, LI Congwu, LEI Lei, ZHANG Qikun, HU Jingjing. An Edge-Cloud Collaborative Cross-Domain Identity-Based Authentication Protocol with Privacy Protection[J]. Chinese Journal of Electronics. doi: 10.1049/cje.2021.00.269
An Edge-Cloud Collaborative Cross-Domain Identity-Based Authentication Protocol with Privacy Protection

Funds:  This work was supported by the National Key Research and Development Program of China( Grant No.2020YFB1712101), The National Natural Science Foundation of China under Grant (No.61772070, 61772477 and 61971380 ), The Key Technologies R and D Program of Henan Province (No.212102210089, 212102210171, 212102210075), and The Collaborative Innovation Special Plan Project of Zhengzhou (Grant No.2021ZDPY0206).
    received his M.S. degree in Beijing University of Posts and Telecommunications in 2009. Now he is a Ph.D. candidate in School of Computer Science and Technology, Beijing Institute of Technology. His main research interest include wireless communications, blockchain, access control,and cloud storage.(Email: sunhaipeng@bit.edu.cn)

    (corresponding author) received the PhD degree in computer science from Beijing Institute of Technology, Beijing, China. She is currently an associate professor in the School of Computer at Beijing Institute of Technology. Her research interests are in the areas of service computing, web intelligence, and information security. (Email: hujingjing@bit.edu.cn)

  • Received Date: 2021-08-01
  • Accepted Date: 2021-09-28
  • Available Online: 2021-11-03
  • Edge-cloud collaborative computing has a wide range of application scenarios. Resource sharing is one of the key technologies to realize various application scenarios. Identity authentication is an important means to ensure the security of resource sharing in various application scenarios. Because the edge-cloud collaborative application scenario is more complex, it involves collaborative operations among different security domains, frequently access and exit application system of mobile terminals. Traditional identity authentication is no longer suitable for complex application scenarios of edgecloud collaborative computing. Therefore, a cross-domain identity authentication protocol based on privacy protection is proposed. The main advantages of the protocol are as follows. 1) Self-certified key generation algorithm: the public/private key pair of the mobile terminal is generated by the terminal members themselves. The identity registration is realized through the correspondence between the self-authenticating public key and the identity to protect the privacy of the individual. It avoids security risks caused by third-party key distribution and key escrow; 2) Crossdomain identity authentication: the alliance keys are calculated among edge servers through blockchain technology. Each edge server uses the alliance keys to sign the identity information of terminals in its domain. Cross-domain identity authentication is realized through the signature authentication of the alliance domain. The cross-domain authentication process is simple and efficient; 3) Revocability of identity authentication: When the mobile terminal has logged off or exited the system, the legal identity of the terminal in the system will also become invalid immediately, so as to ensure the forward and backward security of accessing system resources. Under the hardness assumption of discrete logarithm problem (DLP) and computational Diffie-Hellman(CDH) problem, the security of the protocol is proven, and the efficiency of the protocol is verified.
