作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2013, Vol. 39 ›› Issue (3): 316-320. doi: 10.3969/j.issn.1000-3428.2013.03.063

• 开发研究与设计技术 • 上一篇    

粤港跨境数字证书认证技术研究

王 娟1,2,龙 云3   

  1. (1. 广东外语外贸大学思科信息学院,广州 510420;2. 中山大学资讯管理学院,广州 510275; 3. 佛山市电子口岸有限公司,广东 佛山 528200)
  • 收稿日期:2012-05-11 出版日期:2013-03-15 发布日期:2013-03-13
  • 作者简介:王 娟(1977-),女,讲师、博士研究生,主研方向:数字证书认证技术,网络信息资源;龙 云,硕士
  • 基金资助:
    广东省对外科技合作基金资助项目(2009B050200008);粤港关键领域重点突破基金资助项目(2009Z007);2012年度教育部人文社会科学研究青年基金资助项目(12YJC870023);广东高校优秀青年创新人才培养基金资助项目(396-GK120026)

Study on Digital Certificate Authentication Technology for Guangdong and Hong Kong Cross-border

WANG Juan  1,2, LONG Yun   3   

  1. (1. Cisco School of Informatics, Guangdong University of Foreign Studies, Guangzhou 510420, China; 2. School of Information Management, Sun Yat-Sen University, Guangzhou 510275, China; 3. Foshan Electron Port Co., Ltd., Foshan 528200, China)
  • Received:2012-05-11 Online:2013-03-15 Published:2013-03-13

摘要: 针对粤港两地政策法规未完全规范,以及两地数字证书认证机构(CA)在认证业务声明和证书策略两方面存在差异的问题,分析目前跨域公钥基础设施信任架构,提出一种针对当前两地政策法规未完全规范情况下的跨境认证解决方案。采用签名中转以及证书信任列表技术,构建两地CA互认支撑平台。实践结果证明,该方案适合于点对点的CA互认,为建设中国与上合组织、东盟、澳大利亚等国家和区域的跨境认证奠定了基础。

关键词: 证书策略, 跨境认证, 信任模型, 证书信任列表, 公钥密码学标准, 轻量级目录访问协议

Abstract: Comparing the differences of Guangdong’s Certification Authority(CA) and Hong Kong’s CA in Certificate Practice Statement(CPS) and Certificate Policy(CP), this paper analyses the current cross-domain Public Key Infrastructure(PKI) trust framework, resolves the problem about mutual authentication in the case of the policies and regulations of the two places not fully standardized by transferring the digital signature, and realizes the cross-border authentication by using Certificate Trust List(CTL) trust model. As practice shows, the scheme is suitable for mutual recognition of point-to-point CA and lays the foundations for the mutual authentication between China and other countries or areas such as Shanghai Cooperation Organization, Association of Southeast Asian Nations and Australia.

Key words: certificate policy, cross-border authentication, trust model, Certificate Trust List(CTL), public-key cryptography standard, lightweight directory access protocol

中图分类号: