摘要
分析了IKE第一阶段主模式的交互过程,在CASC(CA-system Supporting Cross-certification)的基础上,提出了一种支持交叉证书的IPSec VPN应用程序接口设计,主要探讨了其中的处理流程和CASC端证书路径构造算法。该设计方案能够使IPSec VPN自动从CASC系统得到含交叉证书的有效证书链,因而能解决应用程序不支持交叉证书的问题。
This paper analyzed the exchange process of Phase 1 using Main Mode of IKE , and proposes a crosscertification supported Application interface design for IPSec VPN based on the CASC (CA-system Supporting Crosscertification) system. The paper mainly discusses the process and the algorithms of building certificate path on the CASC side. The proposed solution enables the automatic retrieve from CASC of valid certificate chain, which contains the cross certificates. Hence it solves the problem that applications do not support the cross certificates.
出处
《微电子学与计算机》
CSCD
北大核心
2007年第7期94-97,101,共5页
Microelectronics & Computer
基金
江苏省自然科学基金项目(BK2004039)