信息安全研究 ›› 2021, Vol. 7 ›› Issue (9): 836-843.

• 学术论文 • 上一篇    下一篇

数字证书安全性研究

陈怡丹  李馥娟   

  1. (江苏警官学院计算机信息与网络安全系 南京  210031)
  • 出版日期:2021-09-13 发布日期:2021-09-13
  • 通讯作者: 李馥娟
  • 作者简介:陈怡丹 主要研究方向为网络安全与执法. 李馥娟 硕士,教授.主要研究方向为计算机网络技术与应用、信息安全.

Research on Security of Digital Certificate

  • Online:2021-09-13 Published:2021-09-13

摘要: 公钥基础设施(public key infrastructure,PKI)是基于公钥密码加密技术和数字证书来提供系统安全服务,并验证用户身份合法性的一种体系.在系统介绍PKI体系结构及相关技术实现原理和功能特点的基础上,从网络攻击与防御角度,重点分析RSA算法、USBKey数字证书和证书颁发机制(certificate authority,CA)存在的安全问题,提出相应的解决方法和思路.同时,着重从技术和管理2个层面分析数字证书从申领到应用全过程中存在的安全风险,并有针对出的给出具体的应对策略.

关键词: 数字证书, 公钥密钥加密, 公钥基础设施, RSA算法, 优盾

Abstract:  PKI(Public Key Infrastructure) is a kind of system based on Public Key cryptography and digital certificates to provide system security services and verify user identity legitimacy. Based on the systematic introduction of PKI architecture and related technology implementation principle and functional characteristics, from the perspective of network attack and defense, this paper focuses on the analysis of RSA algorithm, USBKEY digital Certificate and CA (Certificate Authority) existing security problems, and puts forward the corresponding solutions and ideas. At the same time, from two aspects of technology and management, and from apply to the CA to the application of digital certificate, the paper focuses on the analysis of the possible security risks, and finally gives out specific countermeasures.

Key words: digital certificate, public key encryption, public key infrastructure, RSA algorithm, USBKey