摘要
针对PKI系统特点提出的可验证部分密钥托管方案是一种权衡了托管机构和用户双方需求的密钥托管方案,其可验证的特点避免了用户托管时可能有的欺骗行为,而部分密钥托管则限制了托管机构滥用权力的可能.同时,分布式产生用户密钥的方法和不泄漏用户部分私钥信息的性质也避免了“阈下攻击”和“早期恢复”的危险.
Verifiable partial key escrow scheme for PKI balances the needs of individuals with the needs of the trustees. It's verifiable therefore users can not cheat the trustees, and partial key escrow scheme limits the possibility of the trustees to abuse their power. At the same time, it implements a distributed algorithm to generate user's key and never leaks any information of user's partial key. So it can also avoid the danger of "subliminal attack" and "early recovery".
出处
《计算机学报》
EI
CSCD
北大核心
2006年第9期1584-1589,共6页
Chinese Journal of Computers