首页> 外文会议>Distributed Computing Systems Workshops, 2009. ICDCS Workshops '09 >Autonomous Decentralized Root Certification Authority System
【24h】

Autonomous Decentralized Root Certification Authority System

机译:自主分散根证书颁发机构系统

获取原文

摘要

A public key infrastructure (PKI) is a set of elements and procedures needed to create, store, manage, distribute and revoke digital certificates. Its main objective is to bind public keys with respective user identities assuring the uniqueness of these public keys. A PKI must guarantee the reliability of its services, assuring the timeliness of its responses and the continuity of the service despite of the growth in the number of users and the presence of hardware or software failures. Avoiding duplication of public keys due to intentional or involuntary errors is mandatory in a PKI, hence the verification of public keys uniqueness is a fundamental task. In this paper we propose a model in which a PKI is constituted by the following entities: a root certification authority (root-CA) responsible for issuing Authorities' certificates and verifying the uniqueness of the public keys issued on its own or by any of the others authorities belonging to this PKI, a number of certification authorities (CA's) which issue end user's certificates, and a number registration authorities (RA's), which store the user certificates. In our PKI model the root certification authority has a main role and it is clear that could become a bottle neck in a real implementation; in order to avoid this risk, we have tried to benefit from autonomous decentralized systems concepts and have proposed an approach in which the root certification authority has the properties of an ADS, namely on-line expandability, on-line maintenance and fault tolerance. Two are the main contributions of this paper, first we apply ADS concepts in a PKI model and, second show a software implementation of an ADS architecture.
机译:公钥基础结构(PKI)是创建,存储,管理,分发和吊销数字证书所需的一组元素和过程。其主要目的是将公用密钥与相应的用户身份绑定在一起,以确保这些公用密钥的唯一性。尽管用户数量不断增加并且存在硬件或软件故障,但PKI必须保证其服务的可靠性,确保其响应的及时性和服务的连续性。在PKI中,必须避免由于故意或非自愿错误而导致的公钥重复,因此,验证公钥唯一性是一项基本任务。在本文中,我们提出了一种模型,其中PKI由以下实体组成:根证书颁发机构(root-CA),负责颁发颁发机构的证书并验证由其自身或由任何机构发布的公钥的唯一性属于此PKI的其他授权机构,颁发最终用户证书的许多证书颁发机构(CA)和存储用户证书的号码注册机构(RA)。在我们的PKI模型中,根证书颁发机构具有主要作用,很明显,它可能在实际实施中成为瓶颈。为了避免这种风险,我们尝试从自治的分散系统概念中受益,并提出了一种方法,其中根证书颁发机构具有ADS的属性,即在线可扩展性,在线维护和容错能力。本文的两个主要贡献是,首先,我们在PKI模型中应用了ADS概念,其次,展示了ADS体系结构的软件实现。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号