A Design of Certificate Authority Based on Elliptic Curve Cryptography
Yangtao Yuan, Quan Liu, Fen Li · 2010
CA (Certificate Authority) acts as the trusted third party, which serves to issue digital certificates and validate them in PKI (Public Key Infrastructure). Hence it's significant to ensure the CA system's security. The ECC (Elliptic Curve Cryptography) has the advantages of shorter key and higher efficiency, comparing with other public key cryptographies such as RSA. The purpose of this work is to design and implement a CA based on ECC by using Java programming technique, which can sign X.509v3 digital certificate to client and then validate client certificate. In application, the key pair (including public key and private key) can be got from the PKCS#12 (Public Key Cryptography Standard), which is used in encryption, decryption and digital signature. The ECC-based CA is used in the system of DRM (Digital Rights Management) to contribute to confidentiality, authenticity, integrality and non-repudiation in communication.