摘要
本文首先对PKI基本信任模型进行了研究分析和比较,然后针对Intranet特点对常用混合信任模型进行了技术改进。该模型在域内可以根据各自单位的性质和结构,采取不同的信任模型。而在域间采取环形信任模型,克服了网状模型证书路径复杂的问题。经过综合分析,证明该方法有效降低了信任路径验证的复杂度,减小了证书路径长度,为PKI技术在Intranet中的普及形成了一个可行实用的模型方案。
The basic PKI trust models were analyzed and compared.And then a technical improvement was made in hybrid trust model according to the characteristics of Intranet.The model can take a different trust model in the region,according to the nature and structure of their units.While in the inter-domain take the ring trust model and it overcome the complex problems of mesh model certification path.The comprehensive analysis shows that the method reduces the complexity of the trust path validation effectively,reduces the length of the certification path,and provides a feasible and practical mode plan for the spread of PKI in Intranet.
出处
《网络安全技术与应用》
2011年第5期25-27,共3页
Network Security Technology & Application