基于身份标识的公开密钥管理方案避免了传统PKI模型下繁杂的公钥签发及验证等操作,对于通信带宽有限、结点计算资源有限的MANET来说,具有较强的优势。基于分布式CA的基本思路,采用门限秘密共享体制,提出了一个基于身份标识的MANET公开密钥管理方案,具有较少的通信量与较少的通信环节,能够较好地适应MANET环境。将CA的功能分布到各个网络结点中,克服了传统CA可用性与安全性方面的问题。设计了显式与隐式两种密钥撤销机制,有效地解决了密钥撤销问题。设计了基于时间片的用户密钥定时更新机制,确保了公钥服务的高可用性。
The public key management scheme based on the ID-based cryptography is more applicable to MANET characterized by its limited bandwidth and computation resources for its avoidance of the public key issuance and verification in traditional PK/scheme. An ID-based public key management scheme is put forward. It has less traffic and rounds. The functions of CA are distributed to multiple network nodes to overcome the availability and security problem of tradition CA. Two different mechanisms including explicit and implicit manner are designed to effectively solve the public key revocation problem. The timed public key refresh based on time slice is also established to ensure the high availability of public key service.