作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2008, Vol. 34 ›› Issue (15): 162-163,. doi: 10.3969/j.issn.1000-3428.2008.15.058

• 安全技术 • 上一篇    下一篇

基于OCSP中间件的PKI/PMI时钟同步

赵 朋,周 宇,王晓东   

  1. (宁波大学信息科学与工程学院,宁波 315010)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2008-08-05 发布日期:2008-08-05

PKI/PMI Clock Synchronization Based on OCSP Middleware

ZHAO Peng, ZHOU Yu, WANG Xiao-dong   

  1. (College of Information Science and Engineering, Ningbo University, Ningbo 315010)
  • Received:1900-01-01 Revised:1900-01-01 Online:2008-08-05 Published:2008-08-05

摘要: PKI/PMI体系如果缺乏规范的时钟机制可能产生时钟不同步现象,因此,在可用性和安全性方面存在隐患。该文通过对在线证书状态协议(OCSP)及PMI认证特性的分析,提出一种基于OCSP中间件的时钟同步技术。应用该技术构建的身份认证与访问控制系统可以消除上述隐患,不会明显加重系统负担,或引入额外风险,适用于多数一般性的数字证书应用。

关键词: 权限管理基础设施, 时钟同步, 在线证书状态协议, 网络时间协议

Abstract: The lack of normative clock mechanism in PKI/PMI probably causes asynchronization, thus the infrastructures has hidden defects of usability and security. By analyzing the features of OCSP and PMI, this paper brings a clock synchronization technology based on OCSP middleware to solve the problem. An identity authentication and access control system with the technology can eliminate those defects above, and it neither overtasks the system markedly nor imports extra risk. It is applicable in most common digital certificate application.

Key words: Privilege Management Infrastructure(PMI), clock synchronization, Online Certificate Status Protocol(OSCP), Network Time Protocol (NTP)

中图分类号: