摘要
SPKI证书主要用于访问控制,它强调分布式处理,允许任何拥有公钥、私钥对的实体自由发布证书,根据需要向不同的服务器提交证书,服务器接收证书后分布式地验证证书并自主决定其有效性。SPKI证书使用实体的公钥而不是名字来标识实体。笔者介绍了SPKI机制的基本原理,讨论了SP KI证书结构、有效性条件、5-元组约简、SDSI名字空间及SPKI证书的优点。最后,介绍了基于SPKI的安全多渠道电子支付系统作为SPKI证书在电子支付中的应用实例。
SPKI (Simple Public Key Infrastructure) can be used for access control. It emphasizes decentralization. SPKI certificate can be generated by any keyholder to empower to grant or delegate the authorization in question. The application should commit the SPKI certificate to the server and the server independently decides to offer service or not rather than deciding by Certificate Authority. SPKI certificate largely uses the public keys of entities instead of their names. The certificate of SPKI is applicable to the model of B to C electric commerce. This paper introduces the fundamental theories of SPKI, including the certificate's structure, the principle of 5-tuple reduction, SDSI name, the advantage of SPKI and so on. In the end, the paper instances the SPKI-based multi-channel payment system to illustrate the SPKI certificate.
出处
《重庆大学学报(自然科学版)》
EI
CAS
CSCD
北大核心
2004年第7期86-89,共4页
Journal of Chongqing University
基金
重庆市科技攻关重点项目"基于SPKI的安全多渠道电子支付系统"(7220-13-15)资助