摘要
为解决构建大规模PKI系统,信任体系互联互通问题,在分析对比了目前常用信任模型优缺点的基础上,吸收已有信任模型的优点,尤其是桥信任模型,提出了一种新的信任模型——以PAS(path agent server)路径代理为基础的多级别桥混合信任模型。在该模型中,证书路径的构造由PAS服务器完成,阐述了多级桥信任模型的基本原理及其构建方法,设计了其总体架构,对PAS系统构建的一些关键技术问题提出了解决方法,解决了网状信任模型证书路径循环和不可达的问题,说明了该模型的可行性。
In order to solve the problem of mutual communication of PKI trust system based on the comparison of the often-used trust models and with reference to the advantages of these models, especially the bridge CA model, a new trust model-multilevel bridge trust model based on path agent, is constructed. A path agent server is introduced to construct trust path in this model. The basic principle and building method of the model are given, and the framework of the model is described, and some methods are given to solve some key questions during the implementation. Mesh trust model certificate path cycle and not up to the problem is solved. It shows the feasibility of the model.
出处
《计算机工程与设计》
CSCD
北大核心
2009年第12期2889-2891,共3页
Computer Engineering and Design
关键词
公钥基础设施
路径代理
认证中心
多级桥CA信任模型
路径构造
public key infrastructure
path agent server
certificate authority
multilevel bridge certificate authority model
path constmction