期刊文献+

PKI撤销机制OCSP风险脆弱性研究

RESEARCH ON THE VULNERABILITY OF PKI REVOCATION MECHANISM OCSP
下载PDF
导出
摘要 通过公钥概念和技术实施的提供安全服务的PKI(Public Key Infrastructure)作为Internet安全解决方案得到了越来越多的应用。PKI的主要目的是通过管理密钥和证书,可以为用户建立起一个安全的网络运行环境,使用户可以在多种应用环境下方便地使用加密和数字签名技术,从而保证网上数据的机密性、完整性、有效性。证书撤销技术是制约PKI大规模发展的瓶颈之一,国内外对主流之一的OCSP(Online Certificate Status Protocol)撤销机制的风险研究却尚未开展起来。综合分析了OCSP机制的安全风险和防范措施,填补了在此领域的空白。 Using public key concepts and techniques, PKI (Public Key Infrastructure), implemented for offering security services, as one of Internet security solutions gains more and more applications. The main purpose of PKI technology is to establish a secure network environment for users by key and certificate management, they can conveniently use encryption and digital signature technology in a variety of applications conditions, thus ensure the confidentiality,integrity and effectiveness of online data. Certificate revocation technology is a bottleneck restricting the development of large-scale PKI. Study on risk for one of the mainstream revocation mechanisms OCSP ( Online Certificate Status Protocol) has not yet carried out in both domestic and abroad. In this paper, the analysis of security risks and preventive measures for OCSP will fill the gaps in this area.
作者 张旭 张根度
出处 《计算机应用与软件》 CSCD 北大核心 2008年第11期1-2,11,共3页 Computer Applications and Software
基金 国家自然科学基金(60373021)
关键词 PKI OCSP 风险 PKI OCSP Risk
  • 相关文献

参考文献7

  • 1Berkovits S, Chokhani S, Furlong J. Public Key Infrastructure Study: Final Report [ R] . MITRE Corporation for NIST, 1994.
  • 2John Iliadis, Stefanos Gritzalis, et al. Towards a framework for evaluating certificate status information mechanisms. Computer Communications,2003,26 : 1839 - 1850.
  • 3Jose L, Muiioz, Jordi Forne, et al. Evaluation of certificate revocation pol- icies: OCSP vs. bverissued-CRL, Proceedings of the 13th International Workshop on Database and Expert Systems Applications,IEEE 2002.
  • 4周永彬,卿斯汉,季庆光,张振峰.一种高效和可扩展的OCSP系统[J].通信学报,2003,24(11):93-99. 被引量:7
  • 5Michael Myers, Rich Ankney, Ambarish MAlpani. X. 509 Intemet Public Key Infrastructure Online Certificate Status Protocol (OCSP) [ S]. RFC2560. PKIX ,2000.
  • 6Russell Housley, Warwick Ford, et al. Internet X. 509 Public Key Infra- structure Certificate and CRL Profile [ S ]. RFC2459. PKIX Working Group, 1999.
  • 7林璟锵,余婧,曹政,冯登国.高性能OCSP服务器的实现[J].计算机工程,2005,31(4):74-76. 被引量:9

二级参考文献9

  • 1张玉清.公钥基础设施(PKI):实现和管理电子安全[M].北京:清华大学出版社,2002..
  • 2冯登国.公开密钥基础设施--概念、标准和实施[M].北京:人民邮电出版社,1998..
  • 3IETF. RFC 2560 X.509 Internet Public Key Infrastructure Online Certificate Status Protocol OCSP. 1999-06
  • 4IETF. RFC 3280 Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile. 2002-04
  • 5Microsoft.Microsoft Developer Network.2001-10?A
  • 6冯登国 周永彬 张振峰 等.密码工程实践指南[M].清华大学出版社,2001.80-83.
  • 7李新,杨义先.OCSP协议分析和实现[J].计算机应用,2002,22(3):7-9. 被引量:14
  • 8李新,任传伦,杨义先.在线证书状态协议的改进及应用[J].计算机工程与应用,2002,38(10):21-22. 被引量:4
  • 9佘 堃,周明天.在线证书状态协议与状态机关[J].计算机研究与发展,2002,39(6):672-677. 被引量:1

共引文献13

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部