电信科学 ›› 2010, Vol. 26 ›› Issue (7): 22-31.doi: 10.3969/j.issn.1000-0801.2010.07.007

• 专题:IPv6技术与应用 • 上一篇    下一篇

IBE-XKMS:一个基于XML的IBE密钥管理服务体系

陈铁明1,2,李 伟1,蔡家楣1,马世龙2   

  1. 1 浙江工业大学计算机科学与技术学院 杭州310023
    2 北京航空航天大学软件开发环境国家重点实验室 北京100191
  • 出版日期:2010-07-15 发布日期:2017-06-20
  • 基金资助:
    软件开发环境国家重点实验室开放课题

IBE-XKMS: XML-Based IBE Key Management Service Infrastructure

Tieming Chen1,2,Wei Li1,Jiamei Cai1,Shilong Ma2   

  1. 1 College of Computer Science and Technology,Zhejiang University of Technology,Hangzhou 310023,China
    2 State Key Laboratory of Software Development Environment,Beihang University,Beijing 100191,China
  • Online:2010-07-15 Published:2017-06-20

摘要:

本文详细分析了基于身份的公钥加密体制(IBE)较PKI在XKMS方面的应用优势,提出了一个面向IBE的XKMS服务体系———IBE-XKMS,阐述了系统管理、身份认证、密钥生成、密钥管理等模块的功能架构以及系统服务的逻辑关系,设计了4类IBE密钥服务,除实现基本的XKMS密钥操作接口外,还设计了支持零客户端安全应用开发的数字信封和数字签名等服务接口,为下一代网络开发环境提供了一个完整的IBE密钥管理服务解决方案。本文实现了一个IBE-XKMS原型系统,并给出IBE-XKMS和PKI-XKMS在密钥服务响应时间和SOAP消息通信量等方面的测试结果,测试结果体现了IBE-XKMS的性能优势。

关键词: PKI, IBE, XKMS, XML, WebService, 密钥管理

Abstract:

In this paper,the differences between PKI and identity-based encryption(IBE)are firstly analyzed,and the advantages of building XKMS infrastructure for IBE are in detail discussed. An XKMS-like service architecture for IBE, named IBE-XKMS, is then proposed, and the modules of system management, identity authentication, key generation and key management are designed, as well as the service component logic relationships are described. Next, the key management service interfaces of four categories are proposed. Besides the basic XKMS services, IBE-XKMS also provides two types of key involved operations to implement the IBE encryption envelope and signature service, which can be utilized to develop some IBE-enabled secure web application without code on client. It is noted that IBE-XKMS provides a service framework with full IBE application supported for the next generation network of web service. At last, a prototype of IBE-XKMS is developed, on which the tests on the service response performance and the SOAP message communication cost are conducted, comparing with that of PKI-enabled XKMS.

Key words: PKI, IBE, XKMS, XML, Web Service, key management

No Suggested Reading articles found!