加窗技术的改进证书吊销机制

An Efficient Certificate Revocation Approach Based on Windowed Revocation Mechanism

  • 摘要: 分析了现有证书吊销机制在灵活性、可升级性和及时性中的缺陷,针对现有新型证书吊销机制,提出了一种结合加窗证书吊销和增量CRL机制的证书吊销机制。该机制结合传统CRL机制和在线证书状态机制的优点,既能满足不同的安全需求,又能有效减少资源开销,满足验证者的实时性证书验证请求。

     

    Abstract: Based on the analysis of the algorithm, performance and problem of a novel certificate revocation approach called the windowed revocation mechanism, a new and more efficient certificate revocation mechanism is proposed in this paper. The new mechanism integrates windowed certificate revocation and Delta-CRL mechanism, and uses effective method to avoid replay-attack.It satisfies the scalability and flexibility requirements of certificate revocation mechanism and, as the same time, can provide near real-time certificate status when required. The design and performance of the new mechanism is analyzed in this paper.

     

/

返回文章
返回