摘要
利用处理基于角色的证书体系的证书图,实现了对SDSI名字证书的处理。基于这种证书图,给出了针对SDSI名字证书的分布式搜索算法,并证明其可靠性和完备性,表明当证书适当存储时,该算法能搜索和找到相关证书并形成证书链。与现有的自下至上的证书搜索算法相比,该算法更好地适应了SDSI名字证书的分布式存储特性。作为有目的的搜索算法,它具备了自下至上算法所不具有的高效性、灵活性,更适合应用于海量证书分散存储的Internet。
Name certificates in SDSI are represented with some certificate graphs which were used to represent role-based certificates. For SDSI name certificates, this paper introduce a distributed searching algorithm based on certificate graphs and prove its soundness and completeness, It shows that the algorithm can search and discovery the related certificates and assemble a certificate chain when all name certificates are stored in an appropriate manner. The algorithm is better suited to the distributed property of storage of SDSI name certificates than the existing bottom-up algorithms. AS a goal-directed algorithm, it is more flexible and efficient than the bottom-up algorithms and has better performance in Internet where millions of certificates are distributed stored.
出处
《计算机应用研究》
CSCD
北大核心
2005年第11期110-113,共4页
Application Research of Computers
基金
国家自然科学基金资助项目(60372046)
关键词
简单的分布式安全基础设施
名字证书
证书链
搜索算法
SDSI(Simple Distributed Security Infrastructure)
Name Certificate
Certificate Chain
Searching Algorithm