CA是PKI中的关键设施.CA的可信任性依赖于CA的私钥。CA的私钥一旦泄露,该CA签发的所有证书就只能全部作废。确保CA的私钥不泄漏极其重要。容忍入侵技术不是通过传统的防火墙或入侵检测技术来保证CA的安全,而是确保当少数部件遭受入侵后,CA系统的机密信息并没有泄漏,即具有容忍入侵性。通过RSA加密算法和(t,n)秘密共享机制,将私钥分发给不同的共享服务器,并且私钥在任何时候都无需重构,保护了CA私钥的保密性,增强了CA的容忍入侵性.关 键 词: 容忍入侵;认证中心;秘密共享A Based Intrusion Tolerant CA Scheme CHAI,zheng-yi,ZHANG,hao-jun(Department of information science and technology,henan university of technology, zhengzhou, henna,China 450007) Abstract:CA is the key infrastructure to the PKI。its reliability relies on its private key。 Once its private key is revealed, all the certificates signed by the CA must be cancelled. so it is very important to ensure the CA private key is not revealed. Intrusion Tolerant ensure the security of the CA by the way that even if some part of the CA is broken, the CA private key is still safe, instead of by the firewall and Intrusion detection. by RSA and (t,n) secret shared method, it distribute private key to different sharing servers. The private key needn’t be reunion at any time to protect the security of the CA and enhance the Intrusion Tolerant of CA.Keywords: Intrusion Tolerant;certificate authority;secret sharing
猜您喜欢
推荐内容
开源项目推荐 更多
热门活动
热门器件
用户搜过
随便看看
热门下载
热门文章
热门标签
评论