首页> 外文会议>Computer Science and Software Engineering, CSSE 2008, 2008 International Conference on >A Decentralized Certification Authority Based on Real World Trust Relationships
【24h】

A Decentralized Certification Authority Based on Real World Trust Relationships

机译:基于真实世界信任关系的去中心化认证中心

获取原文

摘要

The Public key infrastructure (PKI) provides security services for e-commerce, e-government and other cyber transactions. Certification authority (CA), a critical component of PKI, acts as a trust third party (TTP) among these applications. A CA is usually controlled and operated by an authority in real world, which stores and publishes users'' public key and other attributes. However, various types of attributes on certificates are always determined by several authorities instead of a single one. Based on the practical experiences, PKI must be built on real world trust relationships [1], but CAs, registration authorities (RAs) and other commodity PKI components cannotreflect these relationships among authorities well. Although some decentralized CA systems [2, 3] are designed and these CAs are operated by several administrators cooperatively, they focus on the security of CAȁ9;s private key but not the trust relationships among administrators. To the best of our knowledge, no systematic work has been conducted to integrate several real world authorities into a CA, reflecting their trust relationships through system structure. We present a decentralized CA system, which is built and operated on real world trust relationshipsamong several authorities, and issues standard X.509 certificates. Different authorities are responsible for different attributes on certificates, which make the certificates more trust and make the CA more similar to real world.
机译:公钥基础设施(PKI)为电子商务,电子政务和其他网络交易提供安全服务。认证机构(CA)是PKI的关键组成部分,作为这些申请中的信任第三方(TTP)。 CA通常由现实世界中的权限控制和运营,存储和发布用户的公钥和其他属性。但是,证书上的各种类型属性始终由若干当局而不是单个权限确定。基于实践经验,PKI必须建立在真实世界信任关系中[1],但CAS,注册机构(RAS)和其他商品PKI组件不能迅速地在当局之间进行这些关系。虽然设计了一些分散的CA系统[2,3],但这些CAS由若干管理员协同运营,他们专注于CAȁ9;私钥的安全性,但不是管理员之间的信任关系。据我们所知,没有进行系统的工作,以将几个现实世界权限整合到CA中,反映了他们通过系统结构的信任关系。我们提出了一个分散的CA系统,该系统是在现实世界信任关系中构建和运营的,并在若干当局发出标准X.509证书。不同的当局对证书的不同属性负责,这使得证书更加信任并使CA更类似于现实世界。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号