【24h】

A New United Certificate Revocation Scheme in Grid Environments

机译:网格环境中的新的联合证书吊销方案

获取原文
获取原文并翻译 | 示例

摘要

This paper analyses security drawbacks of traditional certificates revocation in GSI. And we bring forward a new united certificate revocation scheme. In our scheme, one-way hash chains, novel multiple certificates and CRLs shared mode are proposed to improve the revocation mechanism. So partial functions of CA are distributed to other Grid nodes, congestion and single-point failure is avoided in Grid environments. The certificates issued by different CAs could carry out mutual authentication, and users can verify the validity of certificates without retrieving the revocation information from the CA which issues the certificates. To study the performance, three classical revocation schemes are used to compare with our united revocation scheme in the experiments. Simulation results and analysis show that the peak request value of united revocation is lower than other three schemes and the peak bandwidth value is narrower and the risk is reduced.
机译:本文分析了GSI中传统证书吊销的安全缺陷。并提出了一种新的统一证书吊销方案。在我们的方案中,提出了单向哈希链,新颖的多证书和CRL共享模式,以改善撤销机制。因此,CA的部分功能可以分配给其他Grid节点,从而避免在Grid环境中出现拥塞和单点故障。由不同的CA颁发的证书可以进行相互认证,并且用户可以验证证书的有效性,而无需从颁发证书的CA检索吊销信息。为了研究性能,在实验中使用了三种经典的撤销方案与我们的统一撤销方案进行了比较。仿真结果和分析表明,联合撤销的峰值请求值低于其他三种方案,峰值带宽更窄,降低了风险。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号