作者: R. Oppliger , A. Greulich , P. Trachsel
关键词:
摘要: Mainly for scalability reasons, many cryptographic security protocols make use of public key cryptography and require the existence a corresponding infrastructure (PKI). A PKI, in turn, consists one or several certification authorities (CAs) that issue revoke certificates users other CAs. Contrary to its conceptual simplicity, establishment operational maintenance CA PKI has aimed our be difficult practice. As viable alternative, this paper proposes an architecture distributed certificate management system (DCMS) can also used provide support group-based access controls. The been prototyped is being by Swiss Federal Strategy Unit Information Technology (FSUIT) protect intranet resources.