【24h】

Certificate Distribution with Local Autonomy

机译:具有本地自治权的证书分发

获取原文
获取原文并翻译 | 示例

摘要

Any security architecture for a wide area network system spanning multiple administrative domains will require support for policy delegation and certificate distribution across the network. Practical solutions will support local autonomy requriements of participating domains by allowing local policies to vary but imposing restrictions to ensure overa-all coherence of the system. This paper describes the design of a such a system to control access to experiments on the ABone active network testbed. This is done through a special-purpose language extending the Query Certificate Manager (QCM) system to include protocols for secure mirroring. Our approach allows significant local autonomy while ensuring global security of the system by integrating verification with retrieval. This enables transparent support for a variety of certificate distribution protocols. We analyze requriements of the ABONE application, describe the design of a security infrastructure for it, and discuss steps toward implementation, testing and deployment of the system.
机译:跨多个管理域的广域网系统的任何安全体系结构都需要支持策略委托和证书在整个网络中的分发。切实可行的解决方案将允许本地策略发生变化,但施加限制以确保系统的整体一致性,从而支持参与域的本地自治要求。本文介绍了这样一种系统的设计,该系统可以控制对ABone有源网络测试台的实验访问。这是通过将查询证书管理器(QCM)系统扩展为包括用于安全镜像的协议的专用语言来完成的。我们的方法允许大量的本地自治,同时通过将验证与检索集成来确保系统的全局安全性。这样就可以透明地支持各种证书分发协议。我们分析ABONE应用程序的需求,描述其安全基础结构的设计,并讨论实现,测试和部署系统的步骤。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号