Merging and extending the PGP and PEM trust models-the ICE-TEL trust model

Merging and extending the PGP and PEM trust models-the ICE-TEL trust model
复制标题

PGP和PEM信任模型的合并和扩展——ICE-TEL信任模型

DOI:
10.1109/65.587045
复制
发表时间:
1997
期刊:
影响因子:
9.3
通讯作者:
Nada Kapidzic Cicovic
Nada Kapidzic Cicovic
中科院分区:
计算机科学2区
文献类型:
--
作者:
D. Chadwick;A. Young;Nada Kapidzic Cicovic

文献摘要

被引文献

相似文献

ICE-TEL项目是一个泛欧洲项目,它正在整个欧洲建立一个基于Internet X.509的认证基础设施,以及一些将使用它的安全应用程序。信任模型指定了用户可以在断言中建立信任的方法,即远程用户确实是他声称的那个人(身份验证),并且他实际上有权访问他请求的服务或信息(授权)。ICE-TEL信任模型基于现有的相当好的隐私(PGP)信任网络和隐私增强的邮件(PEM)信任模型层次结构的合并和扩展,并且被称为层次结构信任模型的网络。网络层次结构模型具有显着的优势,比以前的两个模型,这些都是突出的。本文进一步描述了通过X.509 V3证书中的一些新扩展来实施信任模型的方式,并给出了在不同场景中使用信任模型的示例。
The ICE-TEL project is a pan-European project which is building an Internet X.509-based certification infrastructure throughout Europe plus several secure applications that will use it. This article describes the trust model being implemented by the project. A trust model specifies the means by which a user may build trust in the assertion that a remote user is really who he purports to be (authentication) and that he does in fact, have a right to access the service or information he is requesting (authorization). The ICE-TEL trust model is based on a merging of and extensions to the existing pretty good privacy (PGP) web of trust and privacy-enhanced mail (PEM) hierarchy of trust models, and is called a web of hierarchies trust model. The web of hierarchies model has significant advantages over both previous models, and these are highlighted. The article further describes the way the trust model is enforced through some of the new extensions in the X.509 V3 certificates, and gives examples of its use in different scenarios.