节点文献
一种防窃取的私钥保存及使用方案
Capture-Resilient Private Key Storage and Employment Scheme
【摘要】 目前广泛采用的私钥保存方法是使用用户密码将私钥加密后保存在用户存储设备上,但当该存储设备被攻击者获取时,攻击者很容易使用离线字典猜测攻击获取用户私钥.本文提出一种利用在线服务器协助签名和解密的方法来安全保存并使用用户私钥的方案,用户必须通过在线服务器的认证和协作才能使用存储在用户设备上的私钥.攻击者即使获得用户设备也无法离线猜测用户密码来获取私钥.本方案具有分布式的私钥安全保存,及时的证书撤销和分布式信任管理等优点.
【Abstract】 Common practice of protecting private key from compromise was to encrypt it with a password and store it in the user′s storage device. However, the private key was vulnerabled to offline dictionary attack when the device is captured by an adversary. This paper presents a private key storage and employment scheme which requires the client to authenticate to an online server in order to collaboratively compute the private key cryptographic operations. The proposed scheme has the advantages of secure private key storage, immediate certificate revocation and distributed trust management.
- 【文献出处】 小型微型计算机系统 ,Journal of Chinese Computer Systems , 编辑部邮箱 ,2006年04期
- 【分类号】TN918
- 【被引频次】2
- 【下载频次】79