信息安全研究 ›› 2019, Vol. 5 ›› Issue (11): 1040-1043.

• 技术应用 • 上一篇    下一篇

基于树形桥CA的跨域身份认证解决方案

林俊燕   

  1. 卫士通信息产业股份有限公司
  • 收稿日期:2019-11-08 出版日期:2019-11-15 发布日期:2019-11-20
  • 通讯作者: 林俊燕
  • 作者简介: 林俊燕,(1980.8-),女,硕士,工程师,主要研究领域为网络与信息。lin.junyan@westone.com.cn

Solution of InterDomain Identity Authentication Based on Bridge CA

  • Received:2019-11-08 Online:2019-11-15 Published:2019-11-20

摘要: 在电子政务外网中,网络基础环境复杂,独立CA运营机构很多,形成了各自的证书应用域.如何跨越各个证书应用域,实现统一身份认证涉及2个问题:一是如何标识身份;二是如何鉴别身份.在证书域中,通过证书来标识身份.跨证书域中,信任锚(信任的起点)有多个,首先要解决信任锚之间的信任问题,然后才能说明证书代表的身份信息的唯一性;第二要解决证书的验证的问题,也就是身份鉴别的问题.提出一种基于树形桥CA的跨域身份认证的实现方案,通过桥CA解决多CA的可信问题,通过交叉认证网关实现跨域身份鉴别的问题,并给出了跨域身份认证的实现流程.该解决方案在不改变现有应用场景的前提下,通过构建新的信任链,提出新的鉴别方法,为跨域实体的身份认证提供了解决方案.

关键词: 交叉证书, 桥CA, 跨域认证, 信任传递, 证书路径

Abstract: In the E-government extranet, the basic network environment is complex, and there are many independent CA operating organizations which form their own certificate application domains. How to realize the unified identity authentication across many certificate domains involves two problems, one is how to label the identity uniquely, the other is how to identify the identity. In a certificate domain, identity is identified by a certificate. Across many certificate domains, there are multiple trust anchors (the starting point of trust). The problem of trust between trust anchors should be solved first, and then the uniqueness of identity information represented by the certificate can be explained. The second is to solve the problem of certificate validation, that is, the problem of identity authentication. This paper proposes a solution of inter-domain identity authentication based on bridge CA to solve the problem of multi-CA trust through bridge CA and realize crossdomain identity authentication through interdomain gateway, and presents the implementation process of crossdomain identity. Under the premise of not changing the existing application scenarios, this scheme can well solve the identity authentication problem of crossdomain identity by building a new trust chain and using a new method.K

Key words: cross certificate, bridge CA, trust transfer, inter-domain identity, certificate path