期刊文献+

一种新的数字证书验证方案

A new validation solution for digital certificate
下载PDF
导出
摘要 数字证书是PKI技术的核心,而PKI是网络安全建设的基础.标准的验证数字证书是否有效的过程非常繁杂,对此提出一种新的方案——数字证书的集中式验证方案.方案的基本思想是设置验证服务器,证书使用者作为验证客户向服务器提交请求,由服务器集中验证证书,然后将结果签名发送给客户,完成验证.利用ASN.1语法给出方案的详细描述和安全性分析,并在手机网络环境下与标准的数字证书验证方案进行了性能比较. Digital certificate is the core of PKI,but PKI is the foundation of network security.The standard validation solution for digital certificate is very complex.A new solution is proposed,which is called central validation solution.The main idea of this new solution is that a validation server is established which can centrally validate clients′certificates.Certificate users submit a request to the validation server as validation clients,and the validation server sends the signed validation results to clients after validating certificates centrally.Detailed description with ASN.1of the solution is given.Its security is analyzed,and the performance difference between the new solution and the standard solution in mobile phone network is given.
作者 程震 程雷
出处 《山东理工大学学报(自然科学版)》 CAS 2017年第4期57-60,共4页 Journal of Shandong University of Technology:Natural Science Edition
关键词 数字证书 集中式验证 验证服务器 网络开销 验证策略 digital certificate central validation validation server network overhead validation policies
  • 相关文献

参考文献4

二级参考文献32

  • 1刘霞,古天龙,董荣胜,郭云川.移动环境公平支付协议的设计与分析研究[J].通信学报,2007,28(4):32-37. 被引量:2
  • 2李小勇,桂小林.大规模分布式环境下动态信任模型研究[J].软件学报,2007,18(6):1510-1521. 被引量:137
  • 3谢冬青 冷健.PKI原理与技术[M].北京:清华大学出版社,2003,12..
  • 4Bruce Schneier(美).吴世忠等译.应用密码学:协议、算法和C源程序[M].北京:机械工业出版社,2000
  • 5Wireless Application Protocol Forum,Ltd.Wireless Application Protocol Public Key Infrastructure Definition.http://www.openmobilealliance.org,2001
  • 6Open Mobile Alliance Ltd.Online Certificate Status Protocol Mobile Profile.http://www.openmobilealliance.org,2004
  • 7M Myers,R Ankney,A Malpani et al.RFC2560:X.509 Internet Public Key Infrastructure Online Certificate Status Protocol-OCSP.http://www.ietf.org,1999
  • 8Wireless Application Protocol Forum,Ltd.Wireless Transport Layer Security.http://www.openmobilealliance.org,2001
  • 9NIELSEN R, HAMILTION B A. Observations from the Deployment of a Large Scale PKI [ C ]// Proceedings of 4th Annual PKI R&D Workshop "Multiple Paths to Trust", NIST, Gaithersburg MD, USA, 2005 : 159.
  • 10RIVEST R L. Can We Eliminate Certificate Revocation Lists? [J]. Financial Cryptography, 1998,1465 :178.

共引文献31

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部