J4 ›› 2010, Vol. 32 ›› Issue (11): 55-57.doi: 10.3969/j.issn.1007130X.2010.
• 论文 • Previous Articles Next Articles
ZHU Jiandong1,2,ZHU Zhiting1
Received:
Revised:
Online:
Published:
Abstract:
The security of the CA private key guarantees the credibility of a digital certificate and the validity of the signature. In order to enhance the security protection of the CA private key, we distribute the CA private key to t signature servers with (t,n) secret sharing, each having a different private key sharing, and the private key sharing is periodically updated using the proactive secret scheme. A phasebased RSA signature mechanism is used, each server calculating part of the signature, and then the signed proxy gets the final signature. In the whole process, the CA private key never reconstructs, so it strengthens the safety of the CA private key and the signature. Finally, heterogeneous platforms are used to store the CA secret. VC and OPENSSL are adopted to realize it.
Key words: digital certificates;security of private key;private sharing;stages signature;update of private key
ZHU Jiandong1,2,ZHU Zhiting1. A HighSecurity Scheme of Private Key Protection[J]. J4, 2010, 32(11): 55-57.
0 / / Recommend
Add to citation manager EndNote|Ris|BibTeX
URL: http://joces.nudt.edu.cn/EN/10.3969/j.issn.1007130X.2010.
http://joces.nudt.edu.cn/EN/Y2010/V32/I11/55