期刊文献+

基于桥CA的高兼容性分布式信任模型 被引量:9

A Distributed Trust Model with High-Compatibility Based on Bridge CA
下载PDF
导出
摘要 基于PKI(public-keyinfrastructure)的分布式信任模型能够更好地保证分布式系统的安全性.作为信任路径的载体,数字证书格式的差异性可能对不同信任域实体之间的信任路径的可用性产生影响.提出了证书格式兼容性的概念,并以此为基础分析了证书格式差异对证书有效性验证的作用方式.在桥CA(certificateauthority)的基础上,提出一种兼容性较高的分布式结构的信任模型,能够消除证书格式兼容性问题对不同信任域实体之间实现互连的干扰. Distributed systems could be more secure with distributed trust model based on PKI (public-key infrastructure). The format of certificate may be different among different PKI systems. Those differences may disturb some applications performing verification of the certificate chain. In this paper, how those differences work during mutual verifications is analyzed with the new concept "certificate-format-compatibility". Moreover, a new distributed trust model based on bridge CA (certificate authority) with high compatibility is designed out. Using this trust model, the mutual connections between entities in different trust domains would not be affected by the different certificate formats.
出处 《软件学报》 EI CSCD 北大核心 2006年第8期1818-1823,共6页 Journal of Software
基金 国家自然科学基金 国家重点基础研究发展规划(973)~~
关键词 证书格式 兼容性 桥CA(certificate authority) certificate format compatibility bridge CA (certificate authority)
  • 相关文献

参考文献11

  • 1Weimerskirch A,Thonet G.A distributed light-weight authentication model for Ad-Hoc networks.LNCS,2001,2288:341-354.
  • 2Ma MC,Meinel C.A proposal for trust model:Independent trust intermediary service (ITIS).In:Proc.of the ICWI 2002.2002.785-790.
  • 3Thompson MR,Olson D,Cowles R,Mullen S,Helm M.CA-Based trust model for grid authentication and identity delegation.In:Proc.of the GGF7.2003.
  • 4Xie DQ,Leng J.PKI Principle and Technology.Beijing:Tsinghua University Press,2004.
  • 5Feng DG.Computer and Communication Network Security.Beijing:Tsinghua University Press,2001.
  • 6Adams C,Farrell S.Internet X.509 public key infrastructure certificate management protocols.RFC2510,1999.
  • 7Myers M,Adams C,Solo D,Kemp D.Internet X.509 certificate request message format.RFC2511,1999.
  • 8Chokhani S,Ford W.Internet X.509 public key infrastructure certificate policy and certification practices framework.RFC2527,1999.
  • 9Ford W,Polk W,Solo D.Internet X.509 public key infrastructure certificate and CRL profile.RFC2459,1999.
  • 10Hoffman P.Internet X.509 public key infrastructure operational protocols:FTP and HTTP.RFC2585,1999.

同被引文献85

引证文献9

二级引证文献17

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部