论文部分内容阅读
数字证书是认证系统中的核心,随着公共密钥基础设施(PKI)的建立和认证中心(CA)的建设,用于身份认证和实体鉴别的身份证书已形成了完备的体系。X.509中对身份数字证书的结构、申请、使用、废止等进行了详细的描述,X.509数字身份证书已成为事实上的标准,国内外的CA建设方案大都采用了该证书标准。事实上,认证系统要解决的问题除了身份认证外,另一类重要的应用在于对消息完整性的鉴别,而目前在消息完整性认证理论中却没有提出相应的理论和标准,文章在研究了消息认证的基础上提出了消息数字证书的概念,设计了一类数字消息证书,并对这类数字消息证书的应用与实现中的相关问题进行了探讨。
Digital certificates are the core of the authentication system. With the establishment of the public key infrastructure (PKI) and the establishment of a certification authority (CA), the identity certificates used for identity authentication and entity authentication have formed a complete system. X.509 describes the structure, application, use and abolition of identity digital certificates in detail. The X.509 digital identity certificate has become the de facto standard. Most domestic and foreign CA construction schemes adopt the certificate standard. In fact, the authentication system to solve the problem in addition to identity authentication, another important application lies in the identification of message integrity, and now the message integrity authentication theory did not put forward the corresponding theory and standards, the article studied Based on the message authentication, a concept of message digital certificate is proposed, a type of digital message certificate is designed, and the related problems in the application and realization of such digital message certificate are also discussed.