传统网络中的身份认证工作一般都是由证书权威(CA)来完成,但在分布式的移动Ad Hoe网络中很难实现这种集中式的身份认证机制,引入这样的中心机构会带来潜在的安全威胁,一旦中心机构遭到破坏,将导致整个网络瘫痪,所以只能寻找其它更合适的方式来进行认证.本文提出一种基于绝对信任模型的自组织公钥管理方案,通信实体自己产生公私钥并颁发证书,不需要任何信任第三方以及认证服务器,信任关系按照自然人的可信关系得到可信传播,相对传统的自组织公钥管理,具备更短的平均认证路径长度以及较高的认证通过率,更重要的是,绝对信任证书模型更加符合实际中通信主机之间的信任需求.
In traditional networks, the authentication is performed by certificate authoritys (CA),which can't be built in distributed Ad Hoc Networks however. The centralized CA will bring the potential security threatens and whole network will be destroyed once the CA is invaded. So it is needed to find a more suitable mechanism to perform the authentication. In this paper, we propose a fully self-organized public-key management based on absolute trust model without any centralized authority that allows users to generate their public-private key pairs, to issue certificates, and the trust relation spreads rationally according to the truly human relations. In contrast with the traditional self-Organized Public-Key Management, the average certificates paths get more short ,the authentication pass rates gets more high and the most important is that the absolute based model fits the trust requirement of each host better.