首页 | 本学科首页   官方微博 | 高级检索  
     

CRL增量-过量发布综合模型研究
引用本文:谭良,佘堃,周明天.CRL增量-过量发布综合模型研究[J].计算机科学,2005,32(4):133-136.
作者姓名:谭良  佘堃  周明天
作者单位:电子科技大学计算机科学与工程学院,电子科技大学-卫士通信息安全实验室,成都,610054;四川师范大学软件重点实验室,成都,610066;电子科技大学计算机科学与工程学院,电子科技大学-卫士通信息安全实验室,成都,610054
基金项目:国家863计划项目(863-104-03-01)
摘    要:针对当前PKI应用规模的变化,提出了一种新模型:增量-过量发布综合模型。该模型采用将Delta-CRLs的Base CRL过量发布来实现。通过比较表明,该方式既可以减小信任方下载的CRL大小,改善了响应时间,减少时间碎片;又可以降低对Base CRL峰值请求率,从而降低对存储库的峰值带宽和平均负荷。文中同时指出,增量.过量发布综合模型优于传统模型和增量模型,但其发布性能依赖于PKI系统的证书有效期、证书吊销率、Delta CRL的颁发周期和时间跨度。Delta CRL的颁发周期越长,时间跨度越大,证书吊销率越高,证书有效期越短,过量发布Base CRL所带来的性能优化就越小。因此,增量-过量模型适合于在Delta CRL的颁发周期和时间跨度较短、证书吊销率不高、证书有效期较长的大型PKI系统中。

关 键 词:证书撤消列表(CRL)  增量CRL  过量发布CRL  增量-过量发布  证书吊销率  时间跨度  证书有效期  PKI

Research on the Delta and Over-Issued CRL Synthesis Model
TAN Liang,SHE Kun,ZHOU Ming-Tian.Research on the Delta and Over-Issued CRL Synthesis Model[J].Computer Science,2005,32(4):133-136.
Authors:TAN Liang  SHE Kun  ZHOU Ming-Tian
Affiliation:TAN Liang,SHE Kun,ZHOU Ming-Tian School of Comp. Sci. & Engn.. Univ. of Electronic Sci. & Tech. of China,Information Security United Lab of UESTC-Westone,Chengdu 610054 College of Electronic Engineering,Sichuan Normal University. Chengdu 610066
Abstract:According to the change of application scale of PKI system currently, an improved model: the Delta and over-issued CRL synthesis model is presented, it is realized by that Base CRL of Delta-CRLs is over-issued. Com- pared to other models, the improved model minimizes the size of CRL which can accelerate to response time and time piece, as well as the peak request rate for Base CRL, the peak bandwidth and average loads on CRL repositories. Si- multaneously it is presented in this paper that the improved model is better than traditional model and Delta-CRLs, but the issuance performance of the improved model depends on the rate of certificate revocation, period of certificate validity, time span and issue periods on Delta CRL. Rate of certificate revo-cation is more higher, time span and issue periods on Delta CRL is more longer and period of certificate validity is more shorter, the performance improvement by over-issued Base CRL is more less. So the improved model is fit for the large-scale PKIs whose rate of certificate revo-cation is not high, period of certificate validity is more longer, time span and issue periods on Delta CRL is more shorter.
Keywords:Certificate revocation list(CRL)  Delta-CRLs  Over-issued CRL  Delta and over-issued CRL  Rate of certificate revocation  Time span  Period of certificate validity  PKI
本文献已被 CNKI 维普 万方数据 等数据库收录!
点击此处可从《计算机科学》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号