摘要
在公钥基础设施当中,数字证书有可能在没有到期就要撤销它。PKI主要提供了两种证书撤销方法,就是周期性发布的证书撤销列表CRL和在线证书状态协议OCSP。详细地分析了CRL和OCSP两种证书撤销机制的优点和局限性,结合两者各自的优点,提出了一个高效实用的证书验证机制。给出了该机制的工作原理,并详细地介绍了的实现方法。
In the PKI there is the possibility that the digital certificate is revocated in the due. Two certificates revocating methods are provided in PKI. They are CRL and OCSP, The advantage and disadvantage of CRL and OCSP mechanism are detailedly analysed at first, And a new certificate validating mechanism is put forward by using advantage of CRL and OCSP. Its' principle and realization method are introduced.
出处
《计算机工程与设计》
CSCD
北大核心
2007年第3期536-537,541,共3页
Computer Engineering and Design
关键词
公钥基础设施
数字签名
证书撤销列表
在线证书状态协议
证书状态
数字证书
public key infrastructure
digital signature
certificate revocation list
online certificate status protocol
certificate status
digital certificate