摘要
公钥基础设施PKI是现代网络信息安全领域中的一门新兴主流安全技术。该文分析了基于PKIS规范设计实现的一个PKI安全系统,给出了系统架构和工作流程细节,剖析了系统的局限性。随后介绍了近年新出现的XML安全规范与技术:XML-ENC、XML-SIG、XKMS,基于异构互操作XML安全技术,给出了一个改进的PKI安全系统,即通过增加一个Web服务-可信任服务中间层来分离客户端密钥管理负载,并屏蔽底层异构PKI的复杂性,详细论述了改进新安全系统的优越特性。
Public Key Infrastructure-PKI has become a newly emerging mainstream security technology in the area of modern internet information security.Based on PKIS,a PKI-based security system is designed and implemented,the de-tailed presentation contains system architecture,work flow and analysis on the disadvantage.Then,some new XML secu-rity specifications and technologies:XMI-Enc,XML-SIG,XKMS are introduced,based on these heterogeneous interopera-ble XML technologies,the former PKI-based security system is improved,by inserting a Web service-trust service tier,the load of key management are separated from client end and the underlying heterogeneous PKI complexity can be shielded.Also the advantages of the new architecture are described in detail
出处
《计算机工程与应用》
CSCD
北大核心
2005年第2期109-111,183,共4页
Computer Engineering and Applications
基金
华中科技大学博士后基金项目:基于Globus/Webservics的高性能CFD计算网格研究(编号:AA183107)