作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2009, Vol. 35 ›› Issue (8): 182-185. doi: 10.3969/j.issn.1000-3428.2009.08.062

• 安全技术 • 上一篇    下一篇

基于改进型OCSP的交叉认证方案

张 茜1,2,朱艳琴1,2,罗喜召1,2   

  1. (1. 苏州大学计算机科学与技术学院,苏州 215006;2. 江苏省计算机信息处理技术重点实验室,苏州 215006)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2009-04-20 发布日期:2009-04-20

Cross-certification Scheme Based on Improved OCSP

ZHANG Qian1,2, ZHU Yan-qin1,2, LUO Xi-zhao1,2   

  1. (1. School of Computer Science and Technology, Soochow University, Suzhou 215006;2. Jiangsu Provincial Key Laboratory of Computer Information Processing, Suzhou 215006)
  • Received:1900-01-01 Revised:1900-01-01 Online:2009-04-20 Published:2009-04-20

摘要: 针对在线证书状态协议(OCSP)存在的安全、证书信息源及响应器寻址等问题,提出一种改进型OCSP协议以及一个用于交叉认证系统的设计方案。该方案提高了响应器的性能,在检测证书状态的同时还可建立证书路径并验证其是否有效,避免了因信任域结构不同产生的构建证书路径难的问题。

关键词: 公钥基础设施, 在线证书状态协议, 交叉认证

Abstract: Aiming at the problems in Online Certificate Status Protocol(OCSP) such as security, the information source of certificate and searching address of OCSP responder, this paper proposes an improved OCSP and a scheme based on the improved OCSP for the cross-certification system. The scheme improves the function of the responder, constructs and validates the certificate path when the status of the certificate is given. The scheme avoids the difficulty of constructing the certificate path due to the different architecture of each trust domain.

Key words: Public Key Infrastructure(PKI), Online Certificate Status Protocol(OCSP), cross-certification

中图分类号: