节点文献
基于CRL的证书状态信息发布机制的研究
Research on Certificate Revocation Based on CRL
【摘要】 随着数字证书不断的被接受和使用,人们从中获得了更大的动力寻找各种方法来撤销已停止使用的数字证书,并及时通知终端用户,避免他们使用已被撤销的证书。证书撤销的问题在广域网的PKI产品开发中愈加显得关键。文中阐述了证书撤销的需求与重要性,分析了目前被采用的各种基于CRL的证书状态信息发布机制,并着重讨论了MYPKI中DeltaCRL的实现。
【Abstract】 With the increasing acceptance of digital certificates, now there has been a gaining impetus for methods to nullify the compromised digital certificates and enable the end user to receive this information before trusting a revoked certificate. The problem of certificate revocation is getting more and more crucial with the development of WANbased PKIs. This paper discusses the need and importance of revocation, identifies and analyzes a variety of options that may be considered by those undertaking to address the revocation of digital certificates based on CRL. In addition, this paper also focuese on the implementation of Delta CRL in MYPKI.
【Key words】 Certificate Revocation List(CRL); information security; PKI;
- 【文献出处】 计算机应用 ,Computer Applications , 编辑部邮箱 ,2003年08期
- 【分类号】TP393.08
- 【被引频次】6
- 【下载频次】73