首页 | 本学科首页   官方微博 | 高级检索  
     

一种基于缓存的快速PKI认证模型
引用本文:高志伟,古志民,任小金. 一种基于缓存的快速PKI认证模型[J]. 北京理工大学学报, 2008, 28(1): 58-61,74
作者姓名:高志伟  古志民  任小金
作者单位:北京理工大学,计算机科学技术学院,北京,100081;石家庄铁道学院,计算机系,河北,石家庄,050043;北京理工大学,计算机科学技术学院,北京,100081
摘    要:在大规模PKI系统中跨域建立证书信任时,为提供高效的证书路径发现及认证算法,基于缓存机制提出了一种系统、灵活的认证框架.该框架模型对于短期缓存认证提出一次一密以提高安全性;对于较长时期的证书缓存提出证书可靠性指数概念,让用户可在安全和效率间权衡.扩展证书缓存及证书可靠性指数到CA间的认证,满足实际网络环境需要,提高了认证效率,消除了上层CA证书验证服务时存在的性能瓶颈问题.

关 键 词:缓存  PKI  认证模型
文章编号:1001-0645(2008)01-0058-05
收稿时间:2007-06-08
修稿时间:2007-06-08

A Flexible and Fast PKI Authentication Model Based on Cache Mechanism
GAO zhi-wei,GU Zhi-min and REN Xiao-jin. A Flexible and Fast PKI Authentication Model Based on Cache Mechanism[J]. Journal of Beijing Institute of Technology(Natural Science Edition), 2008, 28(1): 58-61,74
Authors:GAO zhi-wei  GU Zhi-min  REN Xiao-jin
Affiliation:School of Computer Science and Technology; Beijing Institute of Technology; Beijing 100081; China; Department of Computer; Shijiazhuang Railway Institute; Shijiazhuang; Hebei 050043; China;School of Computer Science and Technology; Beijing Institute of Technology; Beijing 100081;School of Computer Science and Technology; Beijing Institute of Technology; Beijing 100081
Abstract:To establish trust on certificates across multiple domains requires an efficient certification path discovery and authentication algorithm.A systematic and flexible authentication model based on cache mechanism is proposed.The model uses one-time key to achieve more secure level for a shorter time cache.For a longer time cache,the concept of reliability index(RI) is introduced for the certification,with which the end user can take a trade off between security and efficiency.To meet the practical network environment,the authentication mechanism between the end user and CAs is extended.The authentication time between CAs are reduced,and more importantly,most authentication processes are finished between lower level CAs,so there is no bottleneck problem to occur in the top level CAs,especially the root CA.
Keywords:cache   PKI   authentication model
本文献已被 维普 万方数据 等数据库收录!
点击此处可从《北京理工大学学报》浏览原始摘要信息
点击此处可从《北京理工大学学报》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号