CA system in network computer environment based on server-end private-key storage mechanism
Yiqi Dai · Journal of Tsinghua University(Science and Technology) · 2007
A design and implementation scheme was devised for a certificate authority(CA) system in network computer environments based on a server-end privatekey storage mechanism to solve the conflict between private-key storage demands of the end-entity and the nonstorage character of network computer systems.The scheme was based on the public key infrastructure(PKI) architecture with system security achieved by various means such as random numbers,salt,and multiple round iterations.The scheme also ensures system scalability by assigning key derivation and encryption/decryption operations to the client-end.System implementation tests show that the system complexity and cost are reduced without impairing system security and scalability because external private-key storage equipment is not needed.