首页> 外文期刊>International Journal of Information Security >PKI design based on the use of on-line certification authorities

PKI design based on the use of on-line certification authorities


获取原文并翻译 | 示例


Public-key infrastructures (PKIs) are considered the basis of the protocols and tools needed to guarantee the security of new Internet applications like electronic commerce, government-citizen relationships and digital distribution. This paper introduces a new infrastructure design, Cert'eM, a key management and certification system that is based on the structure of the electronic mail service and on the principle of near-certification. Cert'eM provides a secure means to identify users and distribute their public-key certificates, enhances the efficiency of revocation procedures, and avoids scalability and synchronization problems. Because we have considered the revocation problem as priority in the design process and a big influence in the rest of the PKI components, we have developed an alternative solution to the use of certificate revocation lists (CRLs). This has become one of the strongest points of this new scheme.
机译:公钥基础结构(PKI)被认为是保证新Internet应用程序(如电子商务,政府与公民的关系和数字分发)安全所需的协议和工具的基础。本文介绍了一种新的基础结构设计,即Cert'eM,它是一种基于电子邮件服务的结构并基于近认证原理的密钥管理和认证系统。 Cert'eM提供了一种安全的方法来识别用户并分发其公共密钥证书,提高了吊销过程的效率,并避免了可伸缩性和同步问题。因为我们已将吊销问题视为设计过程中的优先事项,并且对其余的PKI组件产生了很大的影响,所以我们开发了使用证书吊销列表(CRL)的替代解决方案。这已成为该新计划的强项之一。



  • 外文文献
  • 中文文献
  • 专利


京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号