摘要
针对目前PKI系统建设和维护成本过高,对网格规模有一定限制的问题。研究了公钥基础设施PKI的体系结构,以及基于身份的PKI(ID-PKI)的认证框架,并分析了两种设施的优缺点。提出了一个PKI和ID-PKI相结合的网格认证框架,并对其结构、工作思想作了描述,进一步分析了它的安全性和效率。该认证框架比传统的基于X.509证书的PKI认证系统结构简单、灵活,因而较大地提高了认证效率,降低了系统成本,其安全性也是可以保证的。
In view of the excessive cost that public key infrastructure system's construction and maintenance has limited the scale of the grid. The paper has studied the architecture of the public key infrastructure, as well as the authentication architecture of the identity-based PKI, and has analyzed the good and bad points of two kind of infrastructure. It proposed a grid authentication schemewhich unify the PKI and ID-PKI, and has described its structure and the work thought, further has analyzed its security and the efficiency. This authentication architecture is simpler and more nimble than the traditional PKI system structure based on X. 509 certificate, thus it enhances the authentication efficiency, and reduces the cost of system, and its security also was guaranteed.
出处
《电脑开发与应用》
2007年第11期10-12,15,共4页
Computer Development & Applications
基金
山西省高校科技研究开发项目(200611028)