首页> 外文OA文献 >Trust Management for Public Key Infrastructures: Implementing the X.509 Trust Broker
【2h】

Trust Management for Public Key Infrastructures: Implementing the X.509 Trust Broker

机译:公钥基础结构的信任管理:实施X.509信任代理

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

A Public Key Infrastructure (PKI) is considered one of the most important techniques used to propagate trust in authentication over the Internet. This technology is based on a trust model defined by the original X.509 (1988) standard and is composed of three entities: the Certification Authority (CA), the certificate holder (or subject) and the Relying Party (RP). The CA plays the role of a trusted third party between the certificate holder and the RP. In many use cases, this trust model has worked successfully. However on the Internet, PKI technology is currently facing many obstacles that slow down its global adoption. In this paper, we argue that most of these obstacles boil down to one problem, which is the trust issue, i.e. how can an RP trust an unknown CA over the Internet? We demonstrate that the original X.509 trust model is not appropriate for the Internet and must be extended to include a new entity, called the Trust Broker, which helps RPs make trust decisions about CAs. We present an approach to assess the quality of a certificate that is related to the quality of the CA’s policy and its commitment to it. The Trust Broker, which is proposed for inclusion in the 2016 edition of X.509, could follow this approach to give RPs trust information about CAs. Finally, we present a prototype Trust Broker that demonstrates how RPs can make informed decisions about certificates in the context of the Web, by using its services.
机译:公钥基础结构(PKI)被认为是用于通过Internet传播身份验证信任的最重要技术之一。该技术基于原始X.509(1988)标准定义的信任模型,并且由三个实体组成:证书颁发机构(CA),证书持有者(或主体)和依赖方(RP)。 CA扮演证书持有者和RP之间受信任的第三方的角色。在许多用例中,此信任模型已成功运行。但是,在Internet上,PKI技术当前面临许多阻碍其在全球范围内普及的障碍。在本文中,我们认为这些障碍中的大多数归结为一个问题,即信任问题,即RP如何通过Internet信任未知的CA?我们证明了原始的X.509信任模型不适用于Internet,必须进行扩展以包括一个称为Trust Broker的新实体,该实体可以帮助RP做出有关CA的信任决策。我们提供一种评估证书质量的方法,该方法与CA政策及其承诺的质量有关。提议将其包含在X.509的2016版中的信任代理,可以采用此方法为RP提供有关CA的信任信息。最后,我们提供一个原型Trust Broker,该原型演示了RP如何通过使用Web服务在Web上下文中做出有关证书的明智决策。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号