期刊文献+

一种新型的数字证书注销和验证方案

A NEW REVOCATION AND VERIFICATION SCHEME OF DIGITAL CERTIFICATE
在线阅读 下载PDF
导出
摘要 首先分析了PKI环境下数字证书注销和验证的几种基本方案及其局限性 ,提出了证书提供者主动提供证书有效性证据的思想 ,并据此设计了一种新的数字证书注销状态验证方案。该方案通过连续使用Hash函数引入了与时间关联的证书有效性证据 ,其特点是原理简单、分布处理、安全强度高、可实施性强。 This paper, at first, analyzes several methods of certificate revocation and verification widely used in PKI environment, points out their limitation, then gives a new idea that the certificate holder provides validity evidence for certificate actively. Based on this idea a new scheme is proposed. In this scheme, the validity evidence is created with hash function, and is related to the time. The scheme is simple. It has high security and good workability.
出处 《计算机应用》 CSCD 北大核心 2002年第11期50-53,共4页 journal of Computer Applications
关键词 数字证书 注销 验证 公钥基础设施 证书中心 网络安全 信息安全 计算机网络 PKI digital certificate certificate authority certificate revocation
  • 相关文献

参考文献11

  • 1Architecture for Public-key Infrustructure(APKI)[Z].draft 3.the Open Group,May 1998.
  • 2Housley R.,Polk W.,Solo D.RFC 2459,Internet X.509 Public Key Infrastructure Certificate and CRL Profile[S].IETF,January 1999.
  • 3ITU-T.Rec X.509,Information Technology - Open SystemsInterconnection - The Directory: Public-key and Attribute Certificate Frameworks[S].ITU-T,1988.
  • 4Carlisle A.,Steve L.Understanding Public-Key Infrastructure:Concepts,Standards,and Deployment Considerations[M].Indianapolis: Macmillan Technical Publishing,1999.76-80,109-131.
  • 5http://www.ietf.org/html.charters/pkix-charter.html[EB/OL].PKIX Working Group,1998.
  • 6Fox B.,LaMacchia B.Certificate Revocation: Mechanics and Meaning[A].Proc.Financial Cryptology-CRYPTO′98.LNCS 1465[C],1998.158-164.
  • 7Moni N.,Kobbi N.Certificate Revocation and Certificate Update[A].Proc.7th USENIX Security Symposium[C],1998.217-228.
  • 8X.509 Internet Public Key Infrastructure Online Certificate StatusProtocol.OCSP RFC 2560[S],June 1999.
  • 9Micali S.Efficient Certificate Revocation[R].Technical Memo 542b.MIT Laboratory for Computer Science,March 1996.
  • 10Rivest R.Can We Eliminate Certificate Revocation Lists?[A].Proc.Financial Cryptography′98,LNCS 1465[C],1998.178-183.

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部