摘要
影响PKI发展的主要原因之一是CA对证书管理的困难性。该文基于前向安全数字签名的思想,提出了解决这个问题的新方案。该方案利用前向安全数字签名理论和技术,保证了一个PKI系统在CA签名密钥泄露的情况下损失最小;在CA需要更换签名密钥时效率最高;签名中所含有的时间段信息可以取代时间戳,从而省去了其他PKI系统中必须具有的统一的时间戳服务器;保证了证书路径确认的有效性。
One of the major reasons to hinder the development of PKI is the difficulty that certification authorities(CAs )manage certificates.A new solution to solve this problem is proposed base d on the theory of forward -secure digital signature.The scheme utilizes the theory and technology of forward-secure digital signature to guarantee that the loss is the lowest in the case that CA's signing secret key is compromised;it is most efficient when CA has to change its signing secret key;the time information which is included in digital signature can replace time-stamp ,therefore it leaves out the uniform time-stamp server that other PKI systems have to use;it provides the validity of certification path validation.
出处
《计算机工程与应用》
CSCD
北大核心
2003年第19期149-151,163,共4页
Computer Engineering and Applications
基金
国家自然科学基金资助项目(编号:60273089)
陕西省教育厅自然科学研究计划资助项目(编号:00JK266)
关键词
PKI
交叉认证
公钥证书
前向安全
数字签名
PKI ,Cross authentication,Public Key Certificate,Forward-secure,Digital signature