首页 | 本学科首页   官方微博 | 高级检索  
     

证书吊销的线索二叉排序Hash树解决方案
引用本文:王尚平,张亚玲,王育民.证书吊销的线索二叉排序Hash树解决方案[J].软件学报,2001,12(9):1343-1350.
作者姓名:王尚平  张亚玲  王育民
作者单位:1. 西安电子科技大学;西安理工大学计算中心
2. 西安理工大学计算中心
3. 西安电子科技大学
基金项目:国家自然科学基金资助项目(60073052);陕西省教育厅自然科学研究计划资助项目(00JK266)
摘    要:提出了公钥基础设施(publickeyinfrastructure,简称PKI)中证书吊销问题的一个新的解决方案--线索二叉排序Hash树(certificaterevocationthreadedbinarysortedhashtree,简称CRTBSHT)解决方案.目前关于证书吊销问题的主要解决方案有X.509证书系统的证书吊销列表(certificaterevocationlist,简称CRL)、Micali的证书吊销系统(certificaterevocationsystem,简称CRS)、Kocher的证书吊销树(certificaterevocationtree,简称CRT)及Naor-Nissm的2-3证书吊销树(2-3CRT),这些方案均不完善.在CRT系统思想的基础上,利用线索化二叉排序树及Hash树给出的新方案,既继承了CRT证明一个证书的状态(是否被吊销)不需要整个线索二叉树,而只与其中部分相关路径有关的优点,又克服了CRT在更新时几乎需要对整个树重新构造的缺点,新方案在更新时仅需计算相关部分路径的数值.新方案对工程实现具有一定的参考价值.

关 键 词:公钥基础设施  证书权威  公钥证书  证书吊销  数字签名
收稿时间:2000/12/25 0:00:00
修稿时间:5/9/2001 12:00:00 AM

Threaded Binary Sorted Hash Trees Solution Scheme for Certificate Revocation Problem
WANG Shang ping,ZHANG Ya ling and WANG Yu min.Threaded Binary Sorted Hash Trees Solution Scheme for Certificate Revocation Problem[J].Journal of Software,2001,12(9):1343-1350.
Authors:WANG Shang ping  ZHANG Ya ling and WANG Yu min
Abstract:A new solution scheme called certificate revocation threaded binary sorted Hash trees (CRTBSHT) for certificate revocation problem in public key infrastructure (PKI) is proposed in this paper. Previous solution schemes including traditional X.509 certificates system's certificate revocation lists (CRL), Micali's Certificate Revocation System (CRS), Kocher's Certificate Revocation Trees (CRT), and Naro-Nossim's 2-3 certificate revocation trees (2-3CRT), but no one is perfect. The new scheme keeps the good properties of CRT that it is easy to check or prove whether a certificate is revoked which only needs the related path values but does not need the whole CRT values and overcomes the disadvantage of CRT that any update will cause the whole CRT to be conmputed completely. The new scheme has referential value to the PKI engineering practice.
Keywords:public key infrastructure  CA (certification anthority)  public key certificate  certificate revocation  digital signature  
本文献已被 CNKI 维普 万方数据 等数据库收录!
点击此处可从《软件学报》浏览原始摘要信息
点击此处可从《软件学报》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号