P2P网络离散、动态和自治的特点使得传统的认证方法不能很好的解决其认证问题.采用证书和信任值相结合的方式,提出了一个新的认证协议APExSPKI用于解决P2P网络中节点之间的互认证问题.信任值绑定在证书中使得节点在身份认证的同时还可以进行授权和访问控制操作.此外APExSPKI不需要可信服务器的参与,它允许网络中的任何节点参与到认证的过程中来,参与信任值投票并可充当代理节点来为其他节点颁发证书,这充分体现了节点对等、自治的特点.
In this paper, a novel authentication protocol called APExSPKI for P2P networks is proposed with the combination of certificate and trust. Trust being bound to certificate allows peers to perform authorization and access control as well as authentication. In addition, APExSPKI avoids the presence of central trusted authorities and allows every peer in the community to participate in the trust recommendation and be an agent to issue certificates for other peers, which fully embodies the equity and self-government of peers.