摘要
为解决公钥体制过于复杂而难以在资源受限的无线环境中布署的问题,结合轻量级CA(Certification Authority)概念、(t,n)门限机制和椭圆曲线离散对数公钥体制,构建一个适用于无线Mesh网络的轻量型容侵LT-CA(Lite Tolerant CA)方案。分析表明,LT-CA简化了传统基于证书CA公钥产生、验证及管理的复杂性,具有公钥产生轻量化、公钥验证轻量化、无需证书管理的特点;在没有显著增加系统复杂性的情况下,采用门限机制使LT-CA私钥具有容侵能力,可抵御无线环境下易于实施的多种攻击。
In order to solve the problems of complex public key cryptography which is difficult to implement in a re- source-constrained wireless environments, a lite and tolerant CA(LT-CA) infrastructure was proposed which combines threshold mechanism with the idea of lite-CA(Certification authority) and ellipse curve cryptograph(ECC) public key mechanism. Comparing LT-CA with traditional Certification-based CA system, analysis shows LT-CA reduces the com- plications of producing and verifying public keys by generating public/private keys more flexibly and conveniently and it has the added benefit that it is certificateless. Moreover, LT-CA' s private key possesses the ability of intrusion tolerance without obviously increasing the cost of system computing and payloads, and LT-CA can effectively defend against at- tacks that are known to occur in wireless environments.
出处
《计算机科学》
CSCD
北大核心
2013年第12期200-204,232,共6页
Computer Science
基金
国家科技部创新基金项目(10C26216205256)
中国气象局项目([2013]069)资助