论文标题

可靠且安全的文档签名的一次性证书

One-Time Certificates for Reliable and Secure Document Signing

论文作者

Mayr, Lucas, Zambonin, Gustavo, Schardong, Frederico, Custódio, Ricardo

论文摘要

电子文档使用私钥签名,并通过众所周知的公共密钥基础架构模型使用相应的数字证书进行了验证。必须将私钥放在安全的容器中,以便可以重复使用。这使得私钥管理成为公共密钥基础架构的关键组成部分,没有防止答案。因此,现有的解决方案必须采用繁琐且通常昂贵的吊销方法来处理私人密钥妥协。我们提出了一个新的加密密钥管理模型,该模型由长期,不可撤销的数字证书构建,每个证书都绑定到一个文档。我们的模型向要签署的每个新文档提供了独特的数字证书。我们证明,在每个签名后应删除与这些证书相关的私钥,从而消除了存储这些密钥的需求。此外,我们表明这些证书不需要信任任何吊销机制。我们分析了每个文档频繁生成的新密钥对引起的间接费用,提供安全概述并显示了比传统模型的优势。

Electronic documents are signed using private keys and verified using the corresponding digital certificates through the well-known public key infrastructure model. Private keys must be kept in a safe container so they can be reused. This makes private key management a critical component of public key infrastructures with no failproof answer. Therefore, existing solutions must employ cumbersome and often expensive revocation methods to handle private key compromises. We propose a new cryptographic key management model built with long-term, irrevocable digital certificates, each bound to a single document. Our model issues a unique digital certificate for each new document to be signed. We demonstrate that private keys associated with these certificates should be deleted after each signature, eliminating the need to store those keys. Furthermore, we show that these certificates do not require any revocation mechanism to be trusted. We analyze the overhead caused by the frequent generation of new key pairs for each document, provide a security overview and show the advantages over the traditional model.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源