- 1、本文档共22页,可阅读全部内容。
- 2、有哪些信誉好的足球投注网站(book118)网站文档一经付费(服务费),不意味着购买了该文档的版权,仅供个人/单位学习、研究之用,不得用于商业用途,未经授权,严禁复制、发行、汇编、翻译或者网络传播等,侵权必究。
- 3、本站所有内容均由合作方或网友上传,本站不对文档的完整性、权威性及其观点立场正确性做任何保证或承诺!文档内容仅供研究参考,付费前请自行鉴别。如您付费,意味着您自己接受本站规则且自行承担风险,本站不退款、不进行额外附加服务;查看《如何避免下载的几个坑》。如果您已付费下载过本站文档,您可以点击 这里二次下载。
- 4、如文档侵犯商业秘密、侵犯著作权、侵犯人身权等,请点击“版权申诉”(推荐),也可以打举报电话:400-050-0827(电话支持时间:9:00-18:30)。
查看更多
PublicKeyManagement详解
Public Key Management Brent Waters Last Time Saw multiple one-way function candidates for sigs. OWP (AES) Discrete Log Trapdoor Permutation (RSA) Went over RSA-based signatures in detail DSA (Digital Signature Algorithm) Discrete log based signature scheme Similar to El Gamal Signatures 1991 NIST proposed Became first govt. adopted signature scheme Short signatures 2 160-bit components Slow signing and verification Exponentiation Awkward description Security reduces to funny assumption Why DSA standard? RSA Patent (until 2000) Longer sigs ~200 bytes Encryption (Export Controls) DSA Patent Free Short Signatures ~40bytes No encryption Public Key Management Certificates X.509 Standard How do we validate Certificate Auth? Alice must have public key of certificate authority Publish in N.Y. Times Everyone see, adversary cannot forge all Make sure Jayson Blair not on staff Not realistic Ships with Browser or Operating System Done in practice Trust in CA C.A. is trusted If compromised can forge a cert for Bob Attack might be detected CA key should be strongly guarded BBN SafeKeeper: tempest attacks Public Key Generation Algorithm 1) Alice generates pub/priv. key pair sends pub to CA 2) CA verifies Alice knows private key Challenge/response Self-signed certificate 3) CA generates cert and sends to Alice CA doesn’t know Alice’s key Trust models (Symmetric vs Public) Trust models (Symmetric vs Public) Symmetric Online KDC Knows my key If compromised past+future gone (forward security helps—guesses?) Public Offline Knows only public key Harder to do attack Only future messages exposed Cross Domain Certification Hierarchical solution Web of Trust Certificate Revocation Revoke Bob’s certificate Private key is stolen Leaves company, doesn’t own ID Expiration Date in Cert (1 year) CRL Periodically send lists to everyone Long lists, hard to manage OSCP (Online Certificate status protocol) Online authority to answer queries Signing key at
文档评论(0)