摘要
弹性CA是一种使用入侵容忍技术保护CA密钥的CA系统,它采用了新的私钥分割方法加强了系统的安全性,但其使用的密钥分发中心却不利于CA私钥安全.分布式密钥产生方案就是在传统的弹性CA方案的基础上取消了密钥分发中心,使用分布式的密钥产生和分割机制,从而保证了在CA初始化和整个运行过程中,任意t-1(t为门限值)台服务器都不可能窃得CA私钥,大大加强了CA系统安全.
Resilience CA is a CA system which implements an intrusion tolerant algorithm to protect the private key of CA. It enhances the security of system by implementing a new method to split the private key, but it uses a key distribution center to generate the CA-key and this center compromises the private key. Based on the traditional resilence CA scheme, this scheme cancels the key distribution center, and implements a distributed algorithm to generate a shared CA key, so that any t - 1 ( t is the threshold number) servers can't compromise the private key of CA in the initialization and running stage of CA.
出处
《计算机研究与发展》
EI
CSCD
北大核心
2007年第2期230-235,共6页
Journal of Computer Research and Development
关键词
弹性
入侵容忍
CA
分布式
数字签名
resilience
intrusion tolerant
CA
distributed
digital signature