欢迎访问中国科学院大学学报,今天是
论文

临时RSA密钥和OCSP服务器实现

  • 林璟锵 ,
  • 冯登国
展开
  • 信息安全国家重点实验室(中国科学院研究生院) 北京100049

网络出版日期: 2005-01-15

基金资助

国家高技术研究发展计划 ( 863计划 )高安全弹性CA系统技术 (200 2AA144060);信息安全新技术研究 (2003AA144050)资助

Temporary RSA Key and OCSP Server Implementation

  • Lin Jingqiang ,
  • Feng Dengguo
Expand
  • State Key Laboratory of Information Security, Graduate School of the Chinese Academy of Sciences, Beijing 100049, China

Online published: 2005-01-15

摘要

OCSP服务器作为PKI基础设施的重要组成部分,对响应消息进行数字签名的速度是影响服务器响应速度的主要因素。提出一种OCSP服务器的实现方案,利用了短周期的、临时RSA密钥,大大提高了OCSP服务器的性能,同时满足了服务器的安全要求。

本文引用格式

林璟锵 , 冯登国 . 临时RSA密钥和OCSP服务器实现[J]. 中国科学院大学学报, 2005 , 22(1) : 59 -63 . DOI: 10.7523/j.issn.2095-6134.2005.1.009

Abstract

OCSP Server is a key component of PKI .The response interval is influenced mainly by the server' s signature speed .In this article , an implementation of OCSP server is brought forward , which applies short-period , temporary RSA key to sign response message .In addition to satisfying security requirement , the speed of response is improved greatly

参考文献

[1] Carlisle Adams , Steve Lloyd.Understanding public key infrastructure:concepts , standards , and deployment considerations .Macmil lan TechnicalPublishing , 1998

[2] Li X, Yang YX.The analysis and implementation of OCSP .Computer Applications , 2002 , 22(3):7—9 (in Chinese with English abstract)

[3] IETF Network Working group .RFC 2560 X 509 Internet Public Key Infrast ructure Online Certificate Status Protocol-OCSP .1999

[4] Feng DG , Pei DY.Cryptography tutorial .Beijing :S cience Press , 1999(in Chinese)

[5] RSA Laboratories .Has the RSA algori thm been compromi sed as a result of Bernstein' sPaper? 2002 .http : www .rsasecurity .com rsalabs technotesbernstein .html

[6] IETF Network Working Group .RFC 3280 Internet X 509 Public Key Infrastructure Cert if icate and Certifi cate Revocation List (CRL)profi le.2002

[7] RSA Laboratories .A cost-based security analysi s of symmet ric and asymmetric key lengths .2001 .http : www .rsasecurity.com rsalabs bulletinsbulletin13.html

附中文参考文献

[2] 李 新, 杨义先.OCSP 协议分析和实现.计算机应用, 2002, 22(3):7—9

[4] 冯登国, 裴定一.密码学导引.北京:科学出版社.1999

文章导航

/