RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기

    검증서버 그룹핑 기법을 이용한 실시간 인증서 상태 검증 프로토콜 = Online certificate status protocol using validation server grouping

    한글로보기

    https://www.riss.kr/link?id=T10379764

    • 0

      상세조회
    • 0

      다운로드
    서지정보 열기
    • 내보내기
    • 내책장담기
    • 공유하기
    • 오류접수
    인용문이 복사되었습니다.

    부가정보

    다국어 초록 (Multilingual Abstract) kakao i 다국어 번역

    PKI(Public Key Infrastructure) allowing use of Public Key Cryptograph and certificates is required to meet the security requirements in the open network and distributed network environment. A key task in PKI is Certificate Status Validation. Certificates can be revoked even before the validity period expires, for reasons such as changes in the certificate holder's personal data, damages to or exposure of the private key and cancellation of user authority, and they can be revoked on the expiration of the validity period.
    Certificate Status Validation is an important and mandatory task for the validating party based on the PKI. Certificate validation methods under the PKI environment include the CRL(Certificate Revocation List), OCSP(On-line Certificate Status Protocol), SCVP(Simple Certificate Validation Protocol) and DVCS(Data Validation and Certification Server). CRL contains problems in that revocation information is created on a regular basis, real-time referencing is not supported, and the traffic is increased along with file sizes. Although the OCSP Server method provides real-time validation, validation process efficiency could be compromised with the increasing number of users.
    Distributed OCSP server method can cause problems including distribution CRL, load on a particular server, slow validation process, and consistency and security concerns. This paper suggests ways to resolve some of the problems raised in the existing methods, using distributed OCSP server based on group, such as reducing load, maintaining consistency and receiving and transmitting data with enhanced security.
    This paper proposed a model for conducting certificate validation procedures, which had been processed by a single OCSP server, by grouping a number of distributed OCSP servers. Experiments indicated that the Distributed OCSP Server based on Group method outperforms other methods in terms of traffic reduction and average service request response time. The main reason for the proposed model not yielding a better response time is the duration required for receiving certificate revocation information issued by the CA(Certification Authority) in real time.
    In the proposed model, consistency is the key. All OCSP servers must have the same information at all times and CA allows all OCSP servers to use the updated information only after it receives the confirmation message from all OCSP servers.
    There are a few important factors in the proposed model. First is the reduction of traffic. Traffic of all OCSP servers in the same group will be measured based on the threshold and the server with the least load will perform the validation service, thereby reducing the traffic.
    Second is consistency. CA transmits the updated Updated CRL to all OCSP servers in the group and conducts the validation service only after it has received the message that the information has been received successfully by all OCSP servers.
    Third is security. When CA and OCSP servers send and receive information on certificate suspension and revocation, CA uses private key for encryption and transmission, and the recipient OCSP server uses public key to decryptand validate the information, thereby ensuring the security.
    Lastly, in the all or nothing method used to maintain consistency, a time gap can be created when receiving the confirmation message, depending on the status of individual OCSP servers. Due to this time gap, an OCSP server in normal operation can be disregarded or the transmitted Updated CRL can be ignored, which is an issue that needs to be further discussed.
    번역하기

    PKI(Public Key Infrastructure) allowing use of Public Key Cryptograph and certificates is required to meet the security requirements in the open network and distributed network environment. A key task in PKI is Certificate Status Validation. Certifica...

    PKI(Public Key Infrastructure) allowing use of Public Key Cryptograph and certificates is required to meet the security requirements in the open network and distributed network environment. A key task in PKI is Certificate Status Validation. Certificates can be revoked even before the validity period expires, for reasons such as changes in the certificate holder's personal data, damages to or exposure of the private key and cancellation of user authority, and they can be revoked on the expiration of the validity period.
    Certificate Status Validation is an important and mandatory task for the validating party based on the PKI. Certificate validation methods under the PKI environment include the CRL(Certificate Revocation List), OCSP(On-line Certificate Status Protocol), SCVP(Simple Certificate Validation Protocol) and DVCS(Data Validation and Certification Server). CRL contains problems in that revocation information is created on a regular basis, real-time referencing is not supported, and the traffic is increased along with file sizes. Although the OCSP Server method provides real-time validation, validation process efficiency could be compromised with the increasing number of users.
    Distributed OCSP server method can cause problems including distribution CRL, load on a particular server, slow validation process, and consistency and security concerns. This paper suggests ways to resolve some of the problems raised in the existing methods, using distributed OCSP server based on group, such as reducing load, maintaining consistency and receiving and transmitting data with enhanced security.
    This paper proposed a model for conducting certificate validation procedures, which had been processed by a single OCSP server, by grouping a number of distributed OCSP servers. Experiments indicated that the Distributed OCSP Server based on Group method outperforms other methods in terms of traffic reduction and average service request response time. The main reason for the proposed model not yielding a better response time is the duration required for receiving certificate revocation information issued by the CA(Certification Authority) in real time.
    In the proposed model, consistency is the key. All OCSP servers must have the same information at all times and CA allows all OCSP servers to use the updated information only after it receives the confirmation message from all OCSP servers.
    There are a few important factors in the proposed model. First is the reduction of traffic. Traffic of all OCSP servers in the same group will be measured based on the threshold and the server with the least load will perform the validation service, thereby reducing the traffic.
    Second is consistency. CA transmits the updated Updated CRL to all OCSP servers in the group and conducts the validation service only after it has received the message that the information has been received successfully by all OCSP servers.
    Third is security. When CA and OCSP servers send and receive information on certificate suspension and revocation, CA uses private key for encryption and transmission, and the recipient OCSP server uses public key to decryptand validate the information, thereby ensuring the security.
    Lastly, in the all or nothing method used to maintain consistency, a time gap can be created when receiving the confirmation message, depending on the status of individual OCSP servers. Due to this time gap, an OCSP server in normal operation can be disregarded or the transmitted Updated CRL can be ignored, which is an issue that needs to be further discussed.

    더보기

    목차 (Table of Contents)

    • 제목 차례
    • 1. 서론 = 1
    • 1.1. 연구 배경 및 목적 = 1
    • 1.2. 연구 내용 및 범위 = 3
    • 2. 관련연구 = 5
    • 제목 차례
    • 1. 서론 = 1
    • 1.1. 연구 배경 및 목적 = 1
    • 1.2. 연구 내용 및 범위 = 3
    • 2. 관련연구 = 5
    • 2.1 인증기술 = 5
    • 2.1.1 사용자 및 개체 인증방식 = 5
    • 2.1.2 메시지 인증방식 = 7
    • 2.1.3 암호화 방식 = 8
    • 2.2 공개키 기반구조(PKI; Public Key Infrastructure) = 11
    • 2.2.1 인증서(Certificate) = 12
    • 2.2.2 인증기관(CA; Certification Authority) = 14
    • 2.2.3 등록기관(RA; Registration Authority) = 14
    • 2.2.4 디렉토리(Directory) = 15
    • 2.2.5 최종 개체(End-Entity) = 15
    • 2.3 인증서 상태 검증 기법 = 16
    • 2.3.1 인증서 폐지목록(CRL) = 16
    • 2.3.2 온라인 인증서 상태 프로토콜(OCSP) = 20
    • 2.3.3 분산 OCSP(Distributed OCSP) = 23
    • 3. 검증서버 그룹핑 기법 = 26
    • 3.1 검증서버 그룹핑 기법의 구조 = 27
    • 3.1.1 그룹화 고려사항 = 29
    • 3.1.2 검증서버 수 결정 고려사항 = 30
    • 3.1.3 정보 전송 = 31
    • 3.1.4 중복 저장 = 32
    • 3.1.5 CRL 확장과 엔트리 확장 필드 = 33
    • 3.2. 검증서버 그룹핑 기법의 구성 모듈 = 40
    • 3.2.1 인증서 생성 모듈 = 42
    • 3.2.2 인증서 폐지 모듈 = 47
    • 3.2.3 인증서 상태 검증 모듈 = 49
    • 3.2.4 부하분산 모듈 = 57
    • 4. 검증서버 그룹핑 기법의 분석 및 설계 = 60
    • 4.1 부하분산 = 61
    • 4.2 일관성 및 안전성 확보 = 66
    • 4.3 검증서버 그룹핑 기법의 성능평가 = 71
    • 4.3.1 CA의 인증서폐지 정보 생성 = 73
    • 4.3.2 CA와 검증서버간의 네트워크 부하 = 76
    • 4.3.3 검증 서버의 인증서 유효성 검증 서비스 = 78
    • 4.3.4 검증서버와 클라이언트간의 네트워크 부하 = 82
    • 4.3.5 성능분석을 위한 고려사항 = 84
    • 4.3.6 성능분석을 위한 매개변수 = 85
    • 5. 검증서버 그룹핑 기법 실험 및 고찰 = 86
    • 5.1 실험환경 = 86
    • 5.2 실험방법 = 89
    • 5.3 실험결과 = 90
    • 6. 결론 = 99
    • 약어집 = 101
    • 참고 문헌 = 103
    • Abstract = 108
    • 감사의 글 = 112
    더보기

    분석정보

    View

    상세정보조회

    0

    Usage

    원문다운로드

    0

    대출신청

    0

    복사신청

    0

    EDDS신청

    0

    동일 주제 내 활용도 TOP

    더보기

    주제

    연도별 연구동향

    연도별 활용동향

    연관논문

    연구자 네트워크맵

    공동연구자 (7)

    유사연구자 (20) 활용도상위20명

    이 자료와 함께 이용한 RISS 자료

    나만을 위한 추천자료

    해외이동버튼