摘要
CA对证书管理的困难性是影响PKI发展的主要原因。利用前向安全数字签名理论和技术设计了一个证书管理方案,保证了一个PKI系统在CA签名密钥泄露的情况下。如果马上更换签名密钥,则不用对以前颁发的证书做任何处理,使损失最小,效率最高。同时由于签名中所含有的时间段信息,使每个证书都自动包含时间戳,省掉时间戳服务器,节省开销。
The major reasons to hinder the development of PKI are difficulty of certificate authorities (CA) managing certificates. A new solution to solve this problem is proposed based on the theory and technology of forward secure digital signature. The scheme guarantee that the loss is the lowest if CAS signing secret key is compromised. It is most efficient that nothing to do certificate when CA change its signing secret key at once. The time information which is included in digital signature can replace time stamp , therefore , it leaves out the uniform time stamp server that other PKI systems have to use.
出处
《科学技术与工程》
2006年第5期621-624,共4页
Science Technology and Engineering
基金
国家自然科学基金(60173042)资助
关键词
PKI
公钥证书
前向安全
数字签名
PKI public key certificate forward-secure digital signature