摘要
针对目前基于公钥证书的PKI体系所固有的网络开销大,证书往来过于频繁等缺点,提出并分析了基于身份加密体系(IBC体系)的认证架构和互动模型,说明了IBC模型相对于PKI体系结构的优缺点。针对XML签名和XML加密这两个Web-Security核心协议,比较了使用X.509公钥证书体系和IBC无证书方式在SOAP协议中的实现方式。证明了在保证信息安全的同时,使用IBC模型可以大幅降低网络传输内容,提高了SOA体系的效率和可扩展性。
To overcome the shortcomings,such as high-load network communication,and too many credential exchanges caused by conventional certificate-based PKI infrastructure,the identity-based cryptography model and its interaction model were presented in this paper,and its pros and cons to conventional certificate-based PKI system were also discussed. In this paper,we take XML Signatures and XML Encryption as example to show how IBC technology replaces the X.509 certificate public key infrastructure in SOAP protocol. After the evaluation,it is proven that while protected the safety of message,making use of IBC model can greatly reduce network communication cost and increase the efficiency and extensibility in SOA system.
出处
《计算机仿真》
CSCD
北大核心
2010年第9期120-124,共5页
Computer Simulation