计算机应用 ›› 2005, Vol. 25 ›› Issue (03): 548-550.DOI: 10.3724/SP.J.1087.2005.0548

• 信息安全 • 上一篇    下一篇

基于逆向法和证书主体别名属性构造证书路径

黄迎春1,何良生2,蒋凡   

  1. 1.中国科学技术大学计算机科学技术系; 2.中国科学院研究生院信息安全国家重点实验室
  • 出版日期:2005-03-01 发布日期:2005-03-01
  • 基金资助:

    国家 863计划项目(2003AA148050)

Building certificate path based on reverse method and alternative name of certificate subject

HUANG Ying-chun1,HE Liang-sheng2,JIANG Fan1   

  1. 1.Department of Computer Science and Technology, University of Science and Technology of China, Hefei Anhui 230027, China; 2.State Key Laboratory of Information Security,Graduate School of Chinese Academy of Sciences, Beijing 100039, China
  • Online:2005-03-01 Published:2005-03-01

摘要: 用证书主体别名表示信任域内的证书路径,信任域之间的证书路径由各信任域的路径构造代理完成。在同一信任域内,通过比较目的证书主体别名中的证书路径和信任方的信任锚,信任方可以获得最短的证书路径;不同域之间的实体,通过查询路径构造代理获得域间路径,再连接域内证书主体别名中的证书路径,完成证书路径的构造。

关键词: 证书路径, 公钥基础设施, 逆向法, 证书主体别名

Abstract: The certificate path of the inner-realm is described in its subject alternative name, and the certificate path of the inter-realm was implemented by its proxy. In the same realm, the shortest path can be acquired by the sponsor with comparing the path in the subject alternative name of the target’s certificate and the sponsor’s trusted anchors. In the different realm, the path of the inter-realm can be acquired by requesting the proxy of the construction and concatenating the certificate path described in the subject alternative name, thus the construction of the whole certificate path can be implemented.

Key words: certificate path, public key infrastructure, reverse method, alternative name of certifate subject

中图分类号: