摘要
随着数字证书不断的被接受和使用,人们从中获得了更大的动力寻找各种方法来撤销已停止使用的数字证书,并及时通知终端用户,避免他们使用已被撤销的证书。证书撤销的问题在广域网的PKI产品开发中愈加显得关键。文中阐述了证书撤销的需求与重要性,分析了目前被采用的各种基于CRL的证书状态信息发布机制,并着重讨论了MYPKI中DeltaCRL的实现。
With the increasing acceptance of digital certificates, now there has been a gaining impetus for methods to nullify the compromised digital certificates and enable the end user to receive this information before trusting a revoked certificate. The problem of certificate revocation is getting more and more crucial with the development of WANbased PKIs. This paper discusses the need and importance of revocation, identifies and analyzes a variety of options that may be considered by those undertaking to address the revocation of digital certificates based on CRL. In addition, this paper also focuese on the implementation of Delta CRL in MYPKI.
出处
《计算机应用》
CSCD
北大核心
2003年第8期81-83,86,共4页
journal of Computer Applications
基金
电子科学基金(5145010101DZ0233)
电子科大-卫士通联合实验室基金(W060202)