作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2006, Vol. 32 ›› Issue (11): 34-36.

• 博士论文 • 上一篇    下一篇

在线CA的安全增强方案研究

伍忠东1,喻建平2,谢维信2,白银姬2   

  1. 1. 西安电子科技大学电子工程学院,西安 710071;2. 深圳大学信息工程学院,深圳 518060
  • 出版日期:2006-06-05 发布日期:2006-06-05

Study on Security-enhanced Scheme of Online CA

WU Zhongdong1, YU Jianping2, XIE Weixin2, BAI Yinji2   

  1. 1. School of Electronic Engineering, Xidian Univ., Xi’an 710071; 2. College of Information Engineering, Shenzhen Univ., Shenzhen 518060
  • Online:2006-06-05 Published:2006-06-05

摘要: 结合椭圆曲线密码体制、门限密码技术和主动秘密共享方案,提出一种基于椭圆曲线可验证门限数字签名的在线CA安全增强方案。该方案将在线CA的签名私钥分发给多个CA共享服务器,并保证任何少于门限值的在线CA共享服务器无法共谋获取、篡改和破坏CA的签名私钥,从而保护了CA签名私钥的机密性、完整性和可用性。

关键词: 入侵容忍, 认证, 数字签名, 椭圆曲线

Abstract: A security enhanced method of a verifiable threshold signature scheme based on the elliptic curve is presented by adopting threshold cryptography and proactive secret sharing. The private key of signature service of an online CA is distributed to a few sharing servers. A set of sharing servers which are below the threshold can not obtain the private key by colluding each other, and can not interpolate and corrupt the private key. The confidentiality, integrality and availability of the private key are guaranteed.

Key words: Intrusion tolerance, Certification, Digital signature, Elliptic curve

中图分类号: