• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

J4 ›› 2007, Vol. 29 ›› Issue (7): 30-33.

• 论文 • 上一篇    下一篇

一种基于代理签发的PMI特权委托模型

洪帆 张樟   

  • 出版日期:2007-07-01 发布日期:2010-06-02

  • Online:2007-07-01 Published:2010-06-02

摘要:

代理签发服务是X509 2005修正草案中提出的一种新的特权委托方式,该方式实现对证书的代理签发,具有策略易于发布、审计方便、密钥易于维护等优点。通过分析X509 v4(2000)中委托模型的不足,基于X509 2005修正革案中的DIS提出了一个包含代理签发模块的委托模型,并对该模型的性能进行了进一步的分析。

关键词: 特权管理基础设施 代理签发服务 委托 代理签发模块

Abstract:

Delegation issuing service is one of the new delegation modes issued by the X. 509 2005 draft amendment. Delegation issuing of certificates in this fashion gains many advantages such as easy promulgation, convenient audition and facile maintenance and so on. By analyzing the deficiency of the delegati on model in X. 509 v4(2000), this paper presents a new delegation model which includes DIM and is based on DIS. A further analysis on the performance  of this model is carried out.

Key words: (PMI, delegation issuing service (DIS), delegation, delegation issuing module(DIM))