期刊文献+

分段CRL的一种改进方案

An Improved Scheme of Segmented CRL
下载PDF
导出
摘要 证书撤销列表(CRL)是公开密钥基础设施中应用最为广泛的一种证书撤销机制。通过对基本CRL及分段CRL的分析,在分段CRL的基础上,提出了二次分段CRL。对于分段CRL中的尺寸越来越大以至于影响性能的分段,二次分段CRL根据不同于第一次的分段标准对其进行再次分段,改善了分段CRL中由于证书分类不平衡导致的性能下降问题,同时采用将各分段错开更新的方案,降低了CRL的峰值请求率。二次分段CRL由于通信量小,峰值请求率低,可扩展性好,适合于大规模的PKI系统。 CRL is a widespread-used certificate revocation mechanism in PKI. A Secondary Segmented CR, L was put forward based on the analysis of the traditional CRL and the Segmented CRL. Those segments which became bigger and bigger and therefore affecting the performance of the Segmented CRL was segmented the second time based on different standards. The Secondary Segmented CRL improves the decreasing performance of the Segmented CRL due to the unbalanced certificate classification. Furthermore, the peak request rate is reduced by staggering the update time of the segments. The Secondary Segmented CRL can be used in large scale PKI system due to its light network traffic, low peak request rate and great scalability.
出处 《计算机安全》 2010年第4期15-17,共3页 Network & Computer Security
关键词 公开密钥基础设施 证书撤销 证书撤销列表 分段证书撤销列表 二次分段证书撤销列表 PKI certificate revocation CRL Segmented CRL Secondary Segmented CRL
  • 相关文献

参考文献5

  • 1Berkovits S, Chokhani S, Furlong J. Public Key Infrastructure Study: Final R, eport [R] .MITR, E Corporation for NIST, 1994.
  • 2Housley R,Ford W, Polk W and Solo D. Internet X.509 Public Key Infrastructure Certificate and CEL Profile[S]:Internet PoFC2459,1999.
  • 3Myers M, Ankney R, Maipani A,et al. Internet X.509 Public Key Infrastructure Online Certificate Status Protocol-OCSP[S]: Internet RFC 2560,1999.
  • 4Andre R, Mike J,Svein J ,et al Selecting revocation solutions for PKI: proceedings of The Fifth Nordic Workshop on Secure IT Systems [C]. Reykjavik, Iceland: [s.n.],2000:360-376.
  • 5Cooper D.A Model of Certificate Revocation: Proceedings of the Fifteenth Annual Computer Security Applications Conference[C].[S. l. ]:[s.n. ], 1999:256-264.

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部