论文部分内容阅读
认证中心(CA)按照层次结构可分为多级CA和单级CA,大规模安全系统中多采用多级CA。为发挥单级CA的优势,在大规模安全系统中应用单级CA,提出了一种新的单级CA模型。该文比较了单级CA与多级CA各自的优势和不足,设计了新模型中的核心协议,分析了其安全性和负载。新模型保持了对多级CA优势:验证简单,部署和维护成本低,同时克服了单级CA在规模和复杂度上的局限,可进行跨地域证书发放和多层次管理。原型系统已实现。该单级CA可适应大规模安全系统的需要。
Certification Center (CA) according to the hierarchical structure can be divided into multi-level CA and single-level CA, large-scale security system to use multi-level CA. In order to give full play to the advantages of single-level CA, a single-level CA is applied to large-scale security system. A new single-level CA model is proposed. This paper compares the strengths and weaknesses of single-level CA and multi-level CA, designs the core protocol of the new model, and analyzes its security and load. The new model retains the benefits of multistage CA: simple authentication, low deployment and maintenance costs, overcomes the limitations of scale and complexity of single-level CAs, and allows cross-geographic certificate issuance and multi-level management. Prototype system has been realized. This single-level CA accommodates the needs of a large-scale security system.