首页 | 本学科首页   官方微博 | 高级检索  
     

基于单向哈希链和多重证书的网格安全方案
引用本文:刘颖,夏靖波,汪胜荣,刘佳.基于单向哈希链和多重证书的网格安全方案[J].计算机应用与软件,2005,22(10):76-77.
作者姓名:刘颖  夏靖波  汪胜荣  刘佳
作者单位:空军工程大学电讯工程学院,陕西,西安,710077
基金项目:陕西省自然科学基金项目(2004F14).
摘    要:本文分析了网格安全基础设施(Grid Security Infrastructure、GSI)中传统的证书撤销机制存在的问题,并提出了一种新的联合证书撤销方案。该方案使用单向哈希链和多重证书来改进证书撤销机制,CA的部分功能被分散到其它网格节点,避免了网格环境下的拥塞和单点失败。不同CA颁发的证书能够进行交叉认证,用户可以验证证书的有效性而无需从该证书的颁发CA重新获得撤销信息。因此该方案可以保证证书撤销的实时性。为了研究方案性能,和其他三种传统的证书撤销方案进行了对比实验。结果表明,相对传统的证书撤销机制本文所提出的联合证书撤销方案能使峰值请求率降低、峰值带宽变窄、安全风险降低.

关 键 词:网格网格安全基础设施  单向哈希链  多重证书  CRL共享模式  网格节点  证书  安全方案  多重  哈希  单向
收稿时间:2005-07-07
修稿时间:2005-07-07

A NEW GRID SECURITY SCHEME BASED ON ONE-WAY HASH CHAIN AND MULTIPLE CERTIFICATES
Liu Ying,Xia Jingbo,Wang Shengrong,Liu Jia.A NEW GRID SECURITY SCHEME BASED ON ONE-WAY HASH CHAIN AND MULTIPLE CERTIFICATES[J].Computer Applications and Software,2005,22(10):76-77.
Authors:Liu Ying  Xia Jingbo  Wang Shengrong  Liu Jia
Abstract:This paper analyses security drawbacks of traditional certificates revocation in GSI. And we bring forward a new united certificate revocation scheme. In our scheme, one-way hash chains, novel multiple certificates and CRLs shared mode are proposed to improve the revocation mechanism. So partaal functions of CA are distributed to other Grid nodes, congestion and single-point failure is avoided in Grid environments. The certificates issued by different CAs could carry out mutual authentication, and users can verify the validity of certificates without retrieving the revocation information from the CA which issues the certificates. So real-time of certificates revocation can be ensured in our scheme. To study the performance, three classical revocation schemes are used to compare with our united revocation scheme in the experiments. Results show that the peak request value of united revocation is lower than other three schemes and the peak bandwidth value is narrower and the risk is reduced.
Keywords:Grid GSI One-way hash chain Multiple certificates CRL shared mode
本文献已被 CNKI 维普 万方数据 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号