期刊文献+

基于CRL的证书状态信息发布机制的研究 被引量:3

Research on Certificate Revocation Based on CRL
下载PDF
导出
摘要 随着数字证书不断的被接受和使用,人们从中获得了更大的动力寻找各种方法来撤销已停止使用的数字证书,并及时通知终端用户,避免他们使用已被撤销的证书。证书撤销的问题在广域网的PKI产品开发中愈加显得关键。文中阐述了证书撤销的需求与重要性,分析了目前被采用的各种基于CRL的证书状态信息发布机制,并着重讨论了MYPKI中DeltaCRL的实现。 With the increasing acceptance of digital certificates, now there has been a gaining impetus for methods to nullify the compromised digital certificates and enable the end user to receive this information before trusting a revoked certificate. The problem of certificate revocation is getting more and more crucial with the development of WANbased PKIs. This paper discusses the need and importance of revocation, identifies and analyzes a variety of options that may be considered by those undertaking to address the revocation of digital certificates based on CRL. In addition, this paper also focuese on the implementation of Delta CRL in MYPKI.
出处 《计算机应用》 CSCD 北大核心 2003年第8期81-83,86,共4页 journal of Computer Applications
基金 电子科学基金(5145010101DZ0233) 电子科大-卫士通联合实验室基金(W060202)
关键词 证书撤销列表(CRL) 信息安全 PKI Certificate Revocation List(CRL) information security PKI
  • 相关文献

参考文献11

  • 1Adams C, Farrell S. RFC 2510 Internet X. 509 Public Key Infrastructure Certificate Management Protocols[S]. RFC 2510, Internet Engineer Task Force, March 1999.
  • 2Myers M, Adams C, Solo D, et al. RFC2511 Internet X. 509 Certif-icate Request Message Format[ S]. RFC 2511, Internet Engineer Task Force, March 1999.
  • 3Housley R, Polk W, Ford W, et al. RFC 3280 Internet X. 509 Public Key Infrastructure Certificate and Certificate Revocation List(CRL) Profile[ S]. RFC 3280, Internet Engineer Task Force, April2002.
  • 4ITU. Information Technology - Open system interconnection - The Directory: Public-key AndAttribute Certificate Frameworks [ EB/OL]. ITU-T Recommendation X. 509, ITU, 2000.
  • 5Berkovits S, Chokhani S, Furlong JA, et al. Public Key Infrastructure Study: Final Repor[ DB/CD]. Produced by the MITRE Corporation for NIST, Apr. 1994.
  • 6Cooper DA. A model of certificate revocation[ A]. In Proceedings of the Fifteenth Annual Computer Security Applications Conference[ C], 1999.256 -264.
  • 7Adams C, Lloyd S. Understanding Public-Key Infrastructure: Concepts, Standards and Deployment Considerations[ M]. Macmillan Technical Publishing. 1999.
  • 8Collaborative ITU and ISO/IEC meeting on the Directory. Final Proposed Draft Amendment on Certificate Extensions[ Z], April 1999.
  • 9Ames A. Public Key Certificate Revocation Schemes[ D]. Department of Telematics. Norwegian University of Science and Technology, February 2000.
  • 10Cooper DA. A More Efficient Use of Delta-CRLs[ A]. Proceedings of the 2000 IEEESymposium on Security and Privacy [ C], May2000. 190 -202.

同被引文献10

  • 1蒋定德,陈运,陈伟建.PKI机构证书撤销的研究[J].信息安全与通信保密,2005,27(3):92-95. 被引量:5
  • 2周建峰,马玉祥,欧阳雄.PKI信任模型研究[J].电子科技,2006,19(4):75-78. 被引量:7
  • 3[1]R Housley,W Polk,W Ford,et al.RFC 3280 Internet X.509 Public-key Infrastructure Certificate and Certificate Revocation List (CRL) Profile[S].RFC 3280,Internet Engineer Task Force,2002.
  • 4[2]C Adams,S Farrell.RFC 2510 Internet X.509 Public-key Infrastructure Certificate Management Protocols[S].RFC 2510,Internet Engineer Task Force,1999.
  • 5[3]M Myers,C Adams,D Solo,et al.RFC2511 Internet X.509 Certificate Request Message Format[S].RFC 2511,Internet Engineer Task Force,1999.
  • 6[4]ITU.Information Technology - Open System Interconnection the Directory:Public-key and Attribute Certificate Frameworks[M].ITU-T Recommendation X.509,ITU,2000.
  • 7张舰,谭寒生,周明天.PKI中POP的研究[J].计算机应用,2002,22(增刊):52.
  • 8[7]Carlisle Adams,Steve Lloyd.Understanding Public-key Infrastructure:Concepts,Standards and Deployment Considerations[M].Macmillan Technical Publishing,1999.93-121.
  • 9Housley R. Internet X. 509 public key infrastructure certificate and certificate revocation list (CRL) profile[S].RFC3280, 2002.
  • 10Housley R. Internet X. 509 public key infrastructure, certificate and CRL profile[S]. RFC2459, 1999.

引证文献3

二级引证文献5

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部