首页> 外文会议>International Conference on Applied Cryptography and Network Security >RIKE: Using Revocable Identities to Support Key Escrow in PKIs
【24h】

RIKE: Using Revocable Identities to Support Key Escrow in PKIs

机译:超级:使用可撤销的身份支持PKIS中的主要托管

获取原文

摘要

Public key infrastructures (PKIs) are proposed to provide various security services. Some security services such as confidentiality, require key escrow in certain scenarios; while some others such as non-repudiation, prohibit key escrow. Moreover, these two conflicting requirements can coexist for one user. The common solution in which each user has two certificates and an escrow authority backups all escrowed private keys for users, faces the problems of efficiency and scalability. In this paper, a novel key management infrastructure called RIKE is proposed to integrate the inherent key escrow of identity-based encryption (IBE) into PKIs. In RIKE, a user's PKI certificate also serves as a revocable identity to derive the user's IBE public key, and the revocation of its IBE key pair is achieved by the certificate revocation of PKIs. Therefore, the certificate binds the user with two key pairs, one of which is escrowed and the other is not. RIKE is an effective certificate-based solution and highly compatible with traditional PKIs.
机译:拟提议公钥基础设施(PKI)提供各种安全服务。一些安全服务如机密性,需要在某些情况下托管;虽然其他一些如非拒绝拒绝,但禁止关键托管。此外,这两个冲突的要求可以为一个用户共存。每个用户有两个证书和托管权限备份的常见解决方案都备份用户所有托管私钥,面临效率和可扩展性的问题。在本文中,提出了一种名为Rike的新型关键管理基础设施,以将基于Identity的加密(IBE)的固有键托管集成到PKIS中。在RICE中,用户的PKI证书还可作为派生标识来导出用户的IBE公钥,并且通过PKI的证书撤销实现其IBE密钥对的撤销。因此,证书将用户与两个键对绑定,其中一个是托管的,另一个是不是。立场是一种有效的基于证书的解决方案,与传统的PKIS高度兼容。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号