摘要
首先分析了PKI环境下数字证书注销和验证的几种基本方案及其局限性 ,提出了证书提供者主动提供证书有效性证据的思想 ,并据此设计了一种新的数字证书注销状态验证方案。该方案通过连续使用Hash函数引入了与时间关联的证书有效性证据 ,其特点是原理简单、分布处理、安全强度高、可实施性强。
This paper, at first, analyzes several methods of certificate revocation and verification widely used in PKI environment, points out their limitation, then gives a new idea that the certificate holder provides validity evidence for certificate actively. Based on this idea a new scheme is proposed. In this scheme, the validity evidence is created with hash function, and is related to the time. The scheme is simple. It has high security and good workability.
出处
《计算机应用》
CSCD
北大核心
2002年第11期50-53,共4页
journal of Computer Applications