在三大主要的认证体制PKI,IBE和CPK中,基于身份标识的组合公钥体制CPK拥有我国自主知识产权,解决了大规模认证中密钥管理、离线验证和跨域认证等难题。首先,介绍CPK算法原理;其次,详细分析CPK的体系结构、密钥产生、密钥分发和管理、密钥存储以及密钥更新等问题;再次,对CPK各版本的演进进行介绍;最后,指出CPK有自身的优势应用,其主要运用于身份认证、离线认证、多域和跨域认证。总之,CPK作为一项推动我国信息安全发展的核心技术,有广泛的应用前景。
As one of the three main authentication mechanisms--PKI, IBE and CPK, the identity based combined public key cryptosystem possesses independent intellectual property right, which has solved key management, offline validation, cross domain authentication problems and etc. First of all, the authors introduce the principle of CPK algorithm. Secondly,we analyze in detail the system structure of CPK, key generation, key distribution and management, key storage, and key update. Thirdly, the evolution of all versions of CPK is introduced. Finally, we point out that CPK has the advantage of its own, which is mainly used in identity authentication, offline authentication, multiple domain and cross domain authentication. In conclusion, CPK, which is to promote the development of China' s information security core technology', has a broad application prospect.