期刊文献+

基于LDAP目录服务的OCSP实现模型

LDAP DIRECTORY SERVICE-BASED IMPLEMENTATION MODEL OF OCSP
下载PDF
导出
摘要 提出一种基于LDAP目录服务的OCSP(Online Certificate Status Protocol)实现模型。新模型使用LDAP目录数据库存储OCSP响应器中的证书撤销数据,同时记录实体间证书验证关系;响应器为服务的实体提前收集验证证书的撤销信息,提前准备签名,部分减少了OCSP响应器对撤销数据库的搜索范围和签名时间。实验结果表明,这一方法降低了OCSP平均响应时间,提高了响应器的性能。 This article gives a new implementation model of OCSP based on LDAP directory services.In the new model,data of certificate revocation of OCSP responder is stored in LDAP directory database,and the relationship of certificate authentication between entries is recorded at the same time.The responder gathers revocation information of authentication certificate for serving entries and signs response massage all in advance,it reduces in partial the search scope of revocation database and signing time when response massage constructed.The experimental results show that this model reduces the average response time of OCSP,servers performance is improved as well.
作者 徐蕾 李明
出处 《计算机应用与软件》 CSCD 2010年第4期283-285,共3页 Computer Applications and Software
关键词 证书撤销 LDAP OCSP Certificate revocation Lightweight directory access protocol(LDAP) Online certificate status protocol(OCSP)
  • 相关文献

参考文献4

二级参考文献9

  • 1张玉清.公钥基础设施(PKI):实现和管理电子安全[M].北京:清华大学出版社,2002..
  • 2冯登国.公开密钥基础设施--概念、标准和实施[M].北京:人民邮电出版社,1998..
  • 3IETF. RFC 2560 X.509 Internet Public Key Infrastructure Online Certificate Status Protocol OCSP. 1999-06
  • 4IETF. RFC 3280 Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile. 2002-04
  • 5Microsoft.Microsoft Developer Network.2001-10?A
  • 6Myers M,Ankney R,Malpani A,et al.Internet X.509 Public Key Infrastructure Online Certificate Status Protocol--OCSP[S].RFC 2560,1999-06.
  • 7Marias G F,Papapanagiotou K,Georgiadis P.Caching Alternatives for a MANET-oriented OCSP Scheme[C]//Proc.of 1st IEEE/CREATENET Workshop on Security and QoS in Communication Networks,Athens,Greece.2005-09.
  • 8Muiioz J L,Forne J,Castro J C.Evaluation of Certificate Revocation Policies OCSP VS Overissued-CRL[C]//Proc.of the 13th International Workshop on Database and Expert Systems Applications.2002.
  • 9李新,杨义先.OCSP协议分析和实现[J].计算机应用,2002,22(3):7-9. 被引量:14

共引文献20

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部