论文部分内容阅读
为了解决在网络计算机系统中部署数字证书系统时存在的终端实体对私钥数据的存储需求和网络计算机无本地存储特性的矛盾,提出一种基于服务端密钥存储的网络计算机数字证书应用系统的设计与实现方案。该方案基于公钥基础设施体系架构,采用了随机数、“盐”和多轮迭代等手段保证系统的安全性,并且通过在客户端进行密钥生成和加解密操作的方式实现了系统的可扩展性。系统实现的结果表明:由于无需借助外部密钥存储设备,该系统在保证安全性和可扩展性的同时,实施复杂度和成本均降低。
In order to solve the contradiction between the storage requirements of the private key data and the non-local storage characteristics of the network computer when the digital certificate system is deployed in the network computer system, a network computer digital certificate application system based on the server key storage is proposed Design and implementation of the program. Based on the public key infrastructure architecture, the scheme uses a random number, salt and many rounds of iterations to ensure the security of the system and implements the system by means of key generation and encryption and decryption on the client side Scalability. The results of system implementation show that the system not only needs external key storage device, but also reduces the implementation complexity and cost while ensuring security and scalability.