首页> 外国专利> A method for setting up and carrying out of a secret network safety method in a public key cryptosystem

A method for setting up and carrying out of a secret network safety method in a public key cryptosystem

机译:在公钥密码系统中建立和执行秘密网络安全方法的方法

摘要

Device A in a public key cryptographic network will be constrained to continue to faithfully practice a security policy dictated by a network certification center, long after device A's public key PUMa has been certified. If device A alters its operations from the limits encoded in its configuration vector, for example by loading a new configuration vector, device A will be denied participation in the network. To accomplish this enforcement of the network security policy dictated by the certification center, it is necessary for the certification center to verify at the time device A requests certification of its public key PUMa, that device A is configured with the currently authorized configuration vector. Device A is required to transmit to the certification center a copy of device A's current configuration vector, in an audit record. the certification center then compares device A's copy of the configuration vector with the authorized configuration vector for device A stored at the certification center. If the comparison is satisfactory, then the certification center will issue the requested certificate and will produce a digital signiture dSigPRC on a representation of device A's public key PUMa, using the certification center's private certification key PRC. Thereafter, if device A attempts to change its configuration vector, device A's privacy key PRMa corresponding to the certified public key PUMa, will automatically become unavailable for use in communicating in the network.
机译:公钥加密网络中的设备A将被约束为继续忠实地实践由网络认证中心规定的安全策略,而这是在对设备A的公钥PUMa进行认证之后很长时间的。如果设备A从其配置矢量中编码的限制中更改了其操作,例如通过加载新的配置矢量,则设备A将被拒绝参与网络。为了完成认证中心所规定的网络安全策略的强制实施,认证中心有必要在设备A请求对其公钥PUMa进行认证时,对设备A配置当前授权的配置矢量。设备A需要在审核记录中向认证中心传输设备A当前配置向量的副本。然后,认证中心将设备A的配置向量副本与存储在认证中心的设备A的授权配置向量进行比较。如果比较令人满意,则认证中心将使用认证中心的私有认证密钥PRC在设备A的公开密钥PUMa的表示上颁发请求的证书并生成数字签名dSigPRC。此后,如果设备A尝试更改其配置矢量,则与认证的公共密钥PUMa相对应的设备A的隐私密钥PRMa将自动变得不可用于网络通信。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号