北京工业大学计算机学院,北京,100022
纸质出版:2005
移动端阅览
蔡永泉, 杜秋玲. 一种CA私钥安全管理方案[J]. 电子学报, 2005,33(8):1407-1410.
CAI Yong-quan, DU Qiu-ling. A Secure Scheme for Managing a CA Private Key[J]. Acta Electronica Sinica, 2005, 33(8): 1407-1410.
CA(certificate authority)是PKI中的重要组成部分
负责签发可以识别用户身份的数字证书.CA的私有密钥一旦泄露
它所签发的所有证书将全部作废.因此
保护CA私钥的安全性是整个PKI安全的核心.本文介绍的CA私钥安全管理方案主要基于门限密码技术.通过将不同的密钥份额分布在不同部件上、任何部件都无法重构私钥
来确保在密钥产生、分发及使用过程中
即使部分系统部件受到攻击或系统管理人员背叛
也不会泄漏CA的私钥
CA仍可以正常工作.
CA (certificate authority) is an important component in PKI (Public Key Infrastructure)
and its main task is to issue and sign digital certificates that can identify different users.When the private key of a CA is compromised
all the certificates that are issued by this CA would be revoked.So
keeping the private key secret is the core of the whole PKI security.The secure managing scheme for protecting the private key of a CA recommended in this article is based on threshold cryptography.By storing the private key of a CA in more than one components and by ensuring that any component of the CA is unable to reconstruct the private key
this scheme makes sure that even if some components are compromised or some system administrators betray the private key of the CA would not be leaked and the CA can still work normally in the process of generating
distributing and using the private key.
0
浏览量
756
下载量
4
CSCD
关联资源
相关文章
相关作者
相关机构
京公网安备11010802024621