首页> 外文OA文献 >Trust Management for Public Key Infrastructures: Implementing the X.509 Trust Broker
【2h】

Trust Management for Public Key Infrastructures: Implementing the X.509 Trust Broker

机译:公钥基础结构的信任管理:实施X.509信任代理

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

A Public Key Infrastructure (PKI) is considered one of the most important techniques used to propagate trust in authentication over the Internet. This technology is based on a trust model defined by the original X.509 (1988) standard and is composed of three entities: the certification authority (CA), the certificate holder (or subject), and the Relying Party (RP). The CA plays the role of a trusted third party between the certificate holder and the RP. In many use cases, this trust model has worked successfully. However, we argue that the application of this model on the Internet implies that web users need to depend on almost anyone in the world in order to use PKI technology. Thus, we believe that the current TLS system is not fit for purpose and must be revisited as a whole. In response, the latest draft edition of X.509 has proposed a new trust model by adding new entity called the Trust Broker (TB). In this paper, we present an implementation approach that a Trust Broker could follow in order to give RPs trust information about a CA by assessing the quality of its issued certificates. This is related to the quality of the CA’s policies and procedures and its commitment to them. Finally, we present our Trust Broker implementation that demonstrates how RPs can make informed decisions about certificate holders in the context of the global web, without requiring large processing resources themselves.
机译:公钥基础结构(PKI)被认为是用于通过Internet传播身份验证信任的最重要技术之一。该技术基于原始X.509(1988)标准定义的信任模型,并且由三个实体组成:证书颁发机构(CA),证书持有者(或主体)和依赖方(RP)。 CA扮演证书持有者和RP之间受信任的第三方的角色。在许多用例中,此信任模型已成功运行。但是,我们认为该模型在Internet上的应用意味着Web用户需要依赖世界上几乎任何人才能使用PKI技术。因此,我们认为当前的TLS系统不适合目标,必须从整体上重新审视。作为响应,X.509的最新草案版本通过添加称为“信任代理(TB)”的新实体,提出了一种新的信任模型。在本文中,我们提出了一种信任经纪人可以遵循的实现方法,以便通过评估其颁发的证书的质量为RP提供有关CA的信任信息。这与CA的政策和程序的质量及其对它们的承诺有关。最后,我们介绍了Trust Broker实施,该实施演示了RP如何在全局Web上下文中做出有关证书持有者的明智决策,而无需本身就需要大量处理资源。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号