An Intrusion-tolerant CA System Based on Two-party Secret Sharing and (t,n)Threshold Scheme Mechanism

Minqing Zhang · Jisuanji gongcheng · 2005

After the existing schema is analyzed,a new intrusion-tolerant CA scheme based on a new mechanism,which combines two-party secret sharing arithmetic with(t,n) threshold scheme is proposed.Firstly,CA application sever(CAA) shares secret key of CA with secret sharing server(SS),then the SK 2 of SS is further shared among the n secret sharing server(SSS).During the signature,it not only don’t need to reconstruct theSK 2 byd 2i(1≤i ≤ n) but also to reconstruct the SK byd 2i(1≤i ≤ n) and SK1.The signature is divided into two stage,one is primary signature which is performed in CAA,the other is bis signature which is performed in SS.Before the formation of true signature,CAA and SS would perform mutual authentication,once one of them find the opposing party is in fault,they could give an alarm quickly in this way,the proposed mechanism would improve the security and intrusion-tolerant ability of CA.

Read the paper · More papers on PaperTik