Abstract:
To establish trust on certificates across multiple domains requires an efficient certification path discovery and authentication algorithm.A systematic and flexible authentication model based on cache mechanism is proposed.The model uses one-time key to achieve more secure level for a shorter time cache.For a longer time cache,the concept of reliability index(RI) is introduced for the certification,with which the end user can take a trade off between security and efficiency.To meet the practical network environment,the authentication mechanism between the end user and CAs is extended.The authentication time between CAs are reduced,and more importantly,most authentication processes are finished between lower level CAs,so there is no bottleneck problem to occur in the top level CAs,especially the root CA.