Trust-management subjects face the problem of discovering credential chain. In this paper, the distributed credential chain discovery algorithms in trust-management with parameterized roles are proposed. The algorithms extend the RT0’s and are goal-oriented also. Based on the concept of parameterized roles in RT1, they search the credential graph via the constant matching and variable solving mechanisms. The algorithms can perform chain discovery in most trust-management systems and can support the protection of access control policies during automated trust negotiation. Soundness and completeness of the algorithms are given.
Trust management system has been a promising approach to solve the access control problems in distributed systems. Delegation is a core concept in it and needs to be limited with respect to depth. In this paper, some different delegation depth control approaches in current trust management system are discussed. Then RT+0 is introduced, which incorporates the integer delegation depth control into RT0. The RT+0 credential adds to RT0 depth value, which provides a more expressive power. The changed semantics is formally defined by a translation from credential to Datalog rules. The computational complexity analysis is given and it shows that the semantics is also algorithmically tractable.
In a proxy blind signature scheme, the proxy signer is allowed to generate a blind signature on behalf of the original signer. The proxy blind signature scheme is useful in several applications such as e-voting, e-payment and mobile agent environments. This paper analyzed the security shortcoming of a proxy blind signature scheme which is proposed by Tan et al. Comparing with the weakness of the previous schemes, a new proxy blind signature scheme based DLP is presented to overcome the insecurity. It is proved that this scheme is more secure and efficient than the previous schemes. As an instance, the applying of the schemes in electronic voting is describing.
The problem of fair exchange is a fundamental problem in secure electronic transactions and digital rights management. Park et al. (2003) presented an optimistic fair-exchange protocol based on RSA. Dodis and Reyain (2003) analyzed the vulnerability of Park's scheme and presented an optimistic fair-exchange protocol based on GDH. This paper point out that Dodis and Reyain's scheme is also insecure and inefficient. This work presents a multisignature scheme based on DSA, and describes a novel method of constructing very efficient fair-exchange protocols based on improved DSA signatures. The protocols in this paper are more secure and efficient.
With analyzing the existing on-line electronic payment protocols, this paper presents a new on-line electronic payment protocol named ACSEPP: Anonymous, Convenient and Secure Electronic Payment Protocol. Its aim is to design a practical electronic payment protocol which is both secure and conveinent. Without using PKI_CA frame, it realized the anonymity of consumer and merchant, the convenient of handling, the low cost of maintenance and the security.