作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2007, Vol. 33 ›› Issue (15): 144-146. doi: 10.3969/j.issn.1000-3428.2007.15.050

• 安全技术 • 上一篇    下一篇

基于OCSP方式的证书撤销策略

王 福,谭成翔,刘 欣   

  1. (同济大学计算机系,上海 210031)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2007-08-05 发布日期:2007-08-05

Certificate Revocation Policies Based on OCSP

WANG Fu, TAN Cheng-xiang, LIU Xin   

  1. (Institute of Computer Engineering, Tongji University, Shanghai 210031)
  • Received:1900-01-01 Revised:1900-01-01 Online:2007-08-05 Published:2007-08-05

摘要: 阐述了在线证书状态协议(OCSP)方式的证书撤销机制的原理,针对单服务员模式建立了一个策略评估模型。该模型基于排队理论对系统机制进行了简化和抽象,通过该模型对OCSP方式的证书撤销策略进行评价,结合模型对影响系统的排队时间、网络带宽、验证速度等相关参数进行了讨论,分析了机制中的多服务员模型。

关键词: 在线证书状态协议, 证书撤销列表, PKI, 排队论

Abstract: This paper describes the principle of the mechanism of certificate revocation based on OCSP, and proposes a policy evaluating model focusing on the single service mode of OCSP. The model based on queuing theory simplifies and abstracts the mechanism. According to the model, the revocation policies about OCSP are evaluated, and several parameters effecting on the system such as queuing time, net bandwidth and verifying velocity are discussed. And it analyzes multi-service model.

Key words: on-line certificate status protocol(OCSP), certificate revocation list(CRL), PKI, queuing theory

中图分类号: