节点文献
基于P2P技术的分布式PKI证书撤销列表发布
Distributed Mechanism of Issuing Certificate Revocation List Based on the Technology of P2P
【摘要】 大规模PKI(Public Key Infrastructure)的核心在于数字证书的发放和管理,目前,PKI的管理机构一般采用证书撤消列表(Certificate Revocation List,简称CRL)的方式管理失效证书,但这些发布机制都不能有效地减低服务器端证书存储库的负荷。因此,在P2P技术的基础上,提出了一种分布式的CRL发布机制,该策略不仅在服务器端降低了峰值请求率,而且发挥了P2P网络中资源的版本越多越有利于资源的发现和共享的优点。
【Abstract】 The kernel of PKI is the issuance and management of the figure certificates.The PKI Administration always adopts the methods of Certificate Revocation List("CRL") to summarize the invalidation certificate,but those methods could not reduce the cost of the certificate storage efficiently.This paper put forward a distributed mechanism of issuing CRL based on the technology of P2P.This mechanism not only reduced the peak value of the request rate in the server,but also exerted the advantage of the P2P network in which the resource will be found and shared with facility if the more copies existed.
- 【文献出处】 计算机与数字工程 ,Computer & Digital Engineering , 编辑部邮箱 ,2009年05期
- 【分类号】TP393.08
- 【被引频次】1
- 【下载频次】65