摘要
保护CA私钥的安全性是整个PKI安全的核心.基于RSA公钥算法和(t,n)门限密码技术,采用分阶段签名方案,确保私钥在任何时候都无需重构.同时,在私钥产生、分发及使用过程中,即使部分系统部件受到攻击,也不会泄漏CA的私钥,CA仍可以正常工作.并通过VC和Openssl对系统进行了实现.
Protecting the CA private key is the key issue of the whole PKI. Based on the RSA and ( t, n ) secret shared method and by using the two phrase signature scheme, ensured that it's unnecessary to reunion the private key at any time. While in the proceeding of CA general ted delivered and used, even if some part of the CA is broken, the CA private key is still safe,CA still can work. The system is realized by VC and Openssl.
出处
《河北师范大学学报(自然科学版)》
CAS
北大核心
2008年第3期310-312,共3页
Journal of Hebei Normal University:Natural Science
基金
河南省科技攻关项目(0524220044
0624260017)
河南工业大学自然科学基金(07XJC029)
关键词
容侵
认证中心
秘密共享
CA私钥
intrusion tolerant
certificate authority
secret sharing
CA private key