Font Size: a A A

The Research Of Proxy Certificate Chain Authentication In Grid Environment

Posted on:2007-06-01Degree:MasterType:Thesis
Country:ChinaCandidate:Z H WangFull Text:PDF
GTID:2178360212957188Subject:Software engineering
Abstract/Summary:
As an important component of grid security, authentication and authority is the base of the grid which is widely used. In order to fulfill the light weight mutual authentication, authority and single point sign on, the grid authentication and authority system introduced the definition of X.509 proxy certificate. As X.509 proxy certificate is used more and more frequently that our work in studying and improving the authentication of the proxy certificate chain is more and more meaningful to the grid users.In this document, we will describe and analyze three algorithms: CA certificate path validation, proxy certificate chain validation and a lightweight mutual authentication algorithm based on proxy certificate trust list. Then, we promote two improved algorithms: one is an improved mutual authentication algorithm based on PCTL, another is an improved algorithm of the most common authentication algorithm which worked through abbreviating the length of the chain. In the first algorithm, first of all, we make the PCTL not mapping to a proxy certificate but a Trust Logic Tree, which decreases the number of PCTL in CRA and relieves the burden of CRA. Second, we change a proxy certificate mapping to a PCTL originally to an entry contained in a PCTL, so the CRA could only transfer an entry to acknowledge the validation request of the user. By doing this, the band width required for transferring the validation information will obviously reduced. Third, if the user wants to valid a proxy certificate, it could only search the relate entry in the CRA through the new method and need not ask the CRA to generate a new PCTL any more. This improvement raises the efficiency about the validation of proxy certificate chain. The second algorithm proposes a solution on improving the efficiency of original algorithm in collection of security policy and verification of digital signature, which based on skipping some certificates when verifying Proxy Certificate Chain, as well as combination of a new data structure . We already have a test on this algorithm, the more proxy certificates in the chain and the more times the proxy certificate is used, then, the more obviously in the efficiency improvements of the proxy certificate chain authentication.
Keywords/Search Tags:Grid Security, Proxy Certificate, PC Certificate Chain Validation
Related items