首页> 外国专利> SYSTEM AND METHOD OF SOFTWARE-BASED COMMERCIAL KEY ESCROW FOR PKI ENVIRONMENT

SYSTEM AND METHOD OF SOFTWARE-BASED COMMERCIAL KEY ESCROW FOR PKI ENVIRONMENT

机译:PKI环境下基于软件的商业密钥托管系统和方法

摘要

PURPOSE: A PKI-based commercial key entrusting method and system are provided which provides PKI-roaming service without changing a system and guarantees perfect forward secrecy for a key management server managing a key recovery server. CONSTITUTION: A user A(10) generates a pair of password private key and public key and creates a key recovery block to transmit the key recovery block together with the public key to a registration server(11) in the first step(S201). The registration server transmits the key recovery block and public key to a key managing server(13) at the second step(S202). The key managing server sends a password authentication note issuance permit to the registration server at the third step(S203). The registration server shows the permit to an authentication server(12) and requests a password authentication note with respect to the public key at the fourth step(S204). The authentication server issues the password authentication note and opens the authentication note to a directory server(19) at the fifth step(S205), and transmits the authentication note to the registration server at the sixth step(S206). The registration server delivers the password authentication note to the user A at the seventh step(S207).
机译:目的:提供了一种基于PKI的商业密钥委托方法和系统,其无需改变系统即可提供PKI漫游服务,并为管理密钥恢复服务器的密钥管理服务器保证了完美的前向保密性。构成:用户A(10)生成一对密码私钥和公钥,并创建密钥恢复块,以在第一步(S201)中将密钥恢复块与公钥一起发送给注册服务器(11)。在第二步骤(S202),注册服务器将密钥恢复块和公共密钥发送到密钥管理服务器(13)。密钥管理服务器在第三步骤中向注册服务器发送密码认证票据发行许可(S203)。在第四步骤中,注册服务器向认证服务器(12)显示许可,并针对公共密钥请求密码认证注释。在第五步骤(S205),认证服务器发布密码认证注释,并将认证注释打开到目录服务器(19),并且在第六步骤(S206),将认证注释发送到注册服务器。在第七步骤中,注册服务器将密码认证注释传送给用户A(S207)。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号