A New D-OCSP Mode Based on Distributed Environment
Rui Su · 2004
In this paper a brief explanation about the principle of is given at first and an analysis of Trusted OCSP mode is done which is widely used currently, on the basis of which the problems lying in this mode are pointed out in three aspects: scalability, availability and security. Then a new mode based on distributed environmenti s presented. This mode removes secret information from online RTC responder and places them in RTCA server which stays offline. RTCA generates response proof set according to the status set of all the certificates issued by CA and publishes the proof set to all the RTC responders which use them to process requests sent from relying parties. By this way, distributed solves the issues in scalability, availability and security brought by Trusted OCSP radically and service is optimized as a whole.