欢迎访问中国科学院大学学报,今天是
论文

PKI系统的应用互操作评估

  • 张帆 ,
  • 顾青 ,
  • 荆继武 ,
  • 林璟锵 ,
  • 査达仁
展开
  • 1. 中国科学院研究生院信息安全国家重点实验室,北京 100049;
    2. 国家863计划信息安全基础设施研究中心,上海 200336

收稿日期: 2010-03-02

  网络出版日期: 2010-11-15

基金资助

信息安全国家标准制修订工作项目《PKI系统互操作性评估准则》和电子信息产业发展基金资助 

PKI application interoperability evaluation

  • ZHANG Fan ,
  • GU Qing ,
  • JING Ji-Wu ,
  • LIN Jing-Qiang ,
  • ZHA Da-Ren
Expand
  • 1. State Key Laboratory of Information Security, Graduate University, Chinese Academy of Sciences, Beijing 100049,China;
    2. Information Security Infrastructure Research Center of National 863 Program, Shanghai 200336,China

Received date: 2010-03-02

  Online published: 2010-11-15

摘要

介绍了PKI技术中互操作问题的研究现况,从PKI互操作性与PKI互操作能力的关系入手分析互操作问题,提出一种互操作性评估模型.通过对参与互操作的PKI应用和PKI服务进行互操作能力评估的方法,来提高PKI系统互操作性,解决应用互操作问题.该模型为现有的PKI系统指出了互操作能力改进的方向,有利于建设具有全面互操作能力的PKI系统.

关键词: PKI; 互操作性; 评估

本文引用格式

张帆 , 顾青 , 荆继武 , 林璟锵 , 査达仁 . PKI系统的应用互操作评估[J]. 中国科学院大学学报, 2010 , 27(6) : 824 -830 . DOI: 10.7523/j.issn.2095-6134.2010.6.014

Abstract

In this paper we describe the development of PKI interoperation and analyze the differences between interoperability of PKI transaction and interoperability of PKI entity. We propose a new model of PKI evaluation, which can be used to evaluate the interoperability of PKI entity. The model represents a way to promote interoperability of PKI entity and can be used to construct PKI entity with total interoperability.

参考文献


[1] ITU-T. Recommendation X.509: Information technology -open systems interconnection - the directory: authentication framework
[S].2005:08/05.

[2] Cooper D, Santesson S, Farrell S W, et al. Internet X.509 public key infrastructure certificate and certificate revocation list (CRL) profile
[S]. RFC5280.2008-05.

[3] Myers M, Ankney A, Malpani A, et al. X.509 internet public ley onfrastructure online certificate status protocol
[S]. RFC 2560. 1999-06.

[4] Chokhani S, Ford W, Sabett R. Internet X.509 public key infrastructure certificate policy and certification practices framework. RFC3647. 2003:11.

[5] 公钥密码系列标准 . http://www.rsa.com/rsalabs/node.asp?id=2124.

[6] Steven L. PKI interoperability framework . . http :// www.pkiforum.org/pdfs/PKIInteroperabilityFramework.pdf.

[7] Burr W, Dodson, Nazario N, et al. Minimum interoperability specification for PKI components, Version 1
[S]. NIST Special Publication, 1998.

[8] 冯登国,吴志刚,荆继武.PKI组件最小互操作规范
[S].国家标准GB/T 19771-2005.

[9] 电子认证服务许可证 . . http://www.miit.gov.cn/ n11293472/n11294912/n11296542/12126363.html.

[10] 国家信任源根CA中心 . . http://www.rootca.gov.cn/

[11] Microsoft root certificate program . . http://www.microsoft.com/

[12] WebTrust . . http://webtrust.net/

[13] Federal bridge CA . . http://www.cio.gov/fbca/

[14] European bridge-CA . . http://www.bridge-ca.org/

[15] Institute of Electrical and Electronics Engineers. IEEE standard computer dictionary: A compilation of IEEE standard computer glossaries
[M]. New York:NY,1990.

[16] Common criteria . . http://standards.iso.org/ittf/PubliclyAvailableStandards/c040612_ISO_IEC_15408-1_2005(E).zip.

[17] Polk W, Housley R, Bassham L. Algorithms and identifiers for the internet X.509 public key infrastructure certificate and certificate revocation list (CRL) profile
[S].RFC3279. 2002.

文章导航

/