为了支持多CA环境下的跨信任域认证,实现数字证书互认,构建了基于PKI/CA技术体系的分布式跨域信任平台。设计了该平台的系统结构框架,主要包括可信CA管理与可信CA控制两部分。详细分析了两个子系统的主要功能结构和工作流程,并探讨了平台实现的关键技术机制。结合深圳电子政务实际需求,开发了平台原型系统。应用实例表明,该平台具有较强的灵活性和可扩展性,能够有效解决不同认证体系下的数字证书兼容应用问题。
To support interdomain authentication in the environment of multiCAs and realize recognition of digital certificate, a distributed interdomain trusted platform based on PKI/CA is constructed. Firstly, the corresponding architecture framework is designed. It mainly consists of trusted CA management and trusted CA control. Then the function and workflow are analyzed in detail, and several key technologies for the realization of platform are introduced. Finally, according to the demand for EGovern ment in Shenzhen, the prototype system is develope& Examples show that the platform with strong flexibility and scalability can ef fectively solve digital certificate compatible application problems under different certification systems.