Browse > Article
http://dx.doi.org/10.13089/JKIISC.2004.14.6.15

A Certificate Verification Method based on the Attribute Certificates  

Park ChongHwa (세명대학교)
Kim JiHong (세명대학교)
Lee ChulSoo (경원대학교)
Kim Dongkyoo (아주대학교)
Abstract
Electronic commerce is widely used with the development of information communication technologies in internet using public key certificates. And the study for access control in Web application and DB system is also progressed actively. There are many verification method for PKC(Public Key Certificates), which are CRL, OCSP, SCVP and others. But their certificates verification methods for PKC cannot to be applied to PMI(Privilege Management Infrastructure) which is using AC(Attribute certificates) because of synchronization of PKC and AC. It is because AC has no public key, AC Verifier must get the PKC and verify the validity on PKC and AC. So in this paper we proposed the new AC-based certificate verification model. which provide the synchronization in two certificates(AC and PKC).
Keywords
PKI; PMI; Certificate Verifcation; PKC; AC;
Citations & Related Records
연도 인용수 순위
  • Reference
1 Joon S. Park and Sandhu. 'Smart Certificates: Extending X.509 for Secure Attribute Service on the Web', NISSC / 1999
2 Joon S, Park and Sandhu, 'Binding Identities and Attributes Using Digitally Signed Certificates', ACSAC / 2000
3 RFC 2693, 'SPKI Certification Theory', C. Ellison
4 RFC 3281, 'An Internet Attribute Certificate Profile for Authorization', S, Farrell. April 2002
5 Himanshu Khurana and Virgil D. Gligor. Enforcing Dependencies between PKI Certificates in ad-hoc networks', IEEE International Conference on Tel., Buchartest, Romania, pp. 293-298. June 2001
6 RFC 2459, 'Internet X.509 Public Key Infrastructure Certificate and CRL Profile', IETF PKIX Working Group, January, 1999
7 윤이중, 류재철, '속성인증서 프로화일 연구', 한국정보보호학회 논문지 제11권, 제5호, pp. 75-83, 2001, 10
8 Internet Draft, 'X,509_Ath Edition Draft V8 - Draft ISO/lEC 594-8', May 3, 2001
9 Risa pretty, 'Attribute Certificate', NIST, TWG-99-67, 1999
10 RFC 2560, 'X,509 Internet Public Key Infrastructure Online Certificate Status Protocols - OCSP', IETF PKIX Working Group, 2001