This invention discloses a
certificate-free cross-domain
authentication method in the cloud, comprising deploying
key distribution centers in both the CLC domain and the trusted domain and generating
system parameters; the user and the
cloud service provider (CSP) each applying for partial private keys and combining them with secret values to generate public-key and private-key pairs; the user calculating
authentication information and sending an encrypted request; the CSP verifying the user's legitimacy and returning an encrypted response upon successful
verification; the user receiving the response message, verifying the synchronized valid sequence number and the CSP; upon successful
verification, saving the legitimate provider information, receiving cloud service resources, and establishing a cross-domain
trust relationship and session negotiation key. This invention constructs a
certificate-free cross-domain
authentication method that abandons the complex
certificate chain management of traditional PKI; it adopts a signature and
signcryption-based primitive, balancing data
confidentiality, integrity, and low computational complexity; and through
session key negotiation and a local legitimate user
list caching mechanism, it avoids duplicate authentication and improves
processing efficiency.