检索规则说明:AND代表“并且”;OR代表“或者”;NOT代表“不包含”;(注意必须大写,运算符两边需空一格)
检 索 范 例 :范例一: (K=图书馆学 OR K=情报学) AND A=范并思 范例二:J=计算机应用与软件 AND (U=C++ OR U=Basic) NOT M=Visual
机构地区:[1]北京理工大学计算机科学技术学院
出 处:《北京理工大学学报》2008年第1期58-61,74,共5页Transactions of Beijing Institute of Technology
摘 要:在大规模PKI系统中跨域建立证书信任时,为提供高效的证书路径发现及认证算法,基于缓存机制提出了一种系统、灵活的认证框架.该框架模型对于短期缓存认证提出一次一密以提高安全性;对于较长时期的证书缓存提出证书可靠性指数概念,让用户可在安全和效率间权衡.扩展证书缓存及证书可靠性指数到CA间的认证,满足实际网络环境需要,提高了认证效率,消除了上层CA证书验证服务时存在的性能瓶颈问题.To establish trust on certificates across multiple domains requires an efficient certification path discovery and authentication algorithm. A systematic and flexible authentication model based on cache mechanism is proposed. The model uses one-time key to achieve more secure level for a shorter time cache. For a longer time cache, the concept of reliability index (RI) is introduced for the certification, with which the end user can take a trade off between security and efficiency. To meet the practical network environment, the authentication mechanism between the end user and CAs is extended. The authentication time between CAs are reduced, and more importantly, most authentication processes are finished between lower level CAs, so there is no bottleneck problem to occur in the top level CAs, especially the root CA.
分 类 号:TP309[自动化与计算机技术—计算机系统结构]
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在链接到云南高校图书馆文献保障联盟下载...
云南高校图书馆联盟文献共享服务平台 版权所有©
您的IP:216.73.216.49