摘要
证书撤销机制是影响PKI服务可靠度的关键技术之一。根据撤销机制是否含有CRL服务器建立了两个基于排队论的数学模型,指出在较大规模下应用短周期证书策略是不合适的,并对分段CRL的优越性给出理论证明,最后,结合模型导出参数对实际应用中缓冲器容量的选取进行定性分析。
The mechanism of certificate revocation is one of the key considerations in Public Key Infrastructure(PKI). In the paper two different model of CA are presented, one is a basic model of CA without CRL, the other works with CRL, both of which are based on Queuing Theory. Therefore, it comes to a conclusion that segmented CRL is superior to basic CRL In some extent in theory and some parameters that are used lo choose the buffers of CRL server are put forward at last.
出处
《计算机应用研究》
CSCD
北大核心
2004年第4期68-70,共3页
Application Research of Computers
关键词
证书中心
证书撤销列表
PKI公钥基础结构
排队理论
Certificate Authority
Certificate Revocation List
Public Key Infrastructure (PKI)
Queuing Theory