首页> 外文会议>Annual PKI Research Workshop >Decentralization Methods of Certification Authority Using the Digital Signature Schemes
【24h】

Decentralization Methods of Certification Authority Using the Digital Signature Schemes

机译:使用数字签名方案的认证机构的分散方法

获取原文

摘要

A Public Key Infrastructure (PKI) is the one of the important techniques to support secure e-commerce and digital communications on networks. Many PKI trust models have been proposed and are widely used for various purposes. The trust model that one Certification Authority (CA) issues all certificates is the simplest one. It is called a single CA model. In this model the certificate verification process is very simple, however it is attended with a danger of the high ratio of exposure CA's private key. While a subordinated hierarchical model which is constructed by the multiple CAs can mitigate that risk. For this reason, the distributed CA model like the subordinated hierarchical model is needed in the real world. This paper discusses the advantages and disadvantages of the general distributed CA models. Especially we investigate in two points: (1) the effects in case that the CA's private key is compromised and (2) the certificate path processing. Then we present the new distributed CA models which the certification path is shorter than one of a subordinated hierarchical model by using a forward-secure digital signature scheme and a key-insulated digital signature scheme.
机译:公钥基础架构(PKI)是支持网络安全电子商务和数字通信的重要技术之一。已经提出了许多PKI信任模型,并广泛用于各种目的。一个证书颁发机构(CA)发布所有证书的信任模型是最简单的证书。它被称为单个CA模型。在此模型中,证书验证过程非常简单,但是危险的危险性CA的私钥的高比率危险。虽然由多个CAS构建的次级分层模型可以减轻该风险。因此,在现实世界中需要分布式CA模型等所需的分层模型。本文讨论了一般分布式CA模型的优缺点。特别是我们调查了两点:(1)如果CA的私钥受到损害的情况和(2)证书路径处理的情况。然后,我们通过使用前进安全的数字签名方案和密钥绝缘数字签名方案来提出认证路径的新分布式CA模型。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号