一种CA私钥安全管理方案  被引量:9

A Secure Scheme for Managing a CA Private Key

在线阅读下载全文

作  者:蔡永泉[1] 杜秋玲[1] 

机构地区:[1]北京工业大学计算机学院,北京100022

出  处:《电子学报》2005年第8期1407-1410,共4页Acta Electronica Sinica

基  金:北京市重点学科建设(No.4010001202111)

摘  要:CA(certificateauthority)是PKI中的重要组成部分,负责签发可以识别用户身份的数字证书.CA的私有密钥一旦泄露,它所签发的所有证书将全部作废.因此,保护CA私钥的安全性是整个PKI安全的核心.本文介绍的CA私钥安全管理方案主要基于门限密码技术.通过将不同的密钥份额分布在不同部件上、任何部件都无法重构私钥,来确保在密钥产生、分发及使用过程中,即使部分系统部件受到攻击或系统管理人员背叛,也不会泄漏CA的私钥,CA仍可以正常工作.CA (certificate authority) is an important component in PKI (Public Key Infrastructure) ,and its main task is to issue and sign digital certificates that can identify different users. When the private key of a CA is compromised, all the certificates that are issued by this CA would be revoked.So,keeping the private key secret is the core of the whole PKI security.The secure managing scheme for protecting the private key of a CA recommended in this article is based on threshold cryptography. By storing the private key of a CA in more than one components and by ensuring that any component of the CA is unable to reconstruct the private key,this scheme makes sure that even if some components are compromised or some system administrators betray the private key of the CA would not be leaked and the CA can still work normally in the process of generating,distributing and using the private key.

关 键 词:认证机构 密钥管理 容忍入侵 

分 类 号:TP309[自动化与计算机技术—计算机系统结构]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象