• DocumentCode
    2206928
  • Title

    A Scheme of CA Digital Signature Based on Intrusion Tolerance

  • Author

    Guo, Ping ; Fu, Desheng

  • Author_Institution
    Coll. of Comput. & Software, Nan Jing Univ. of Inf. Sci. & Technol., Nan Jing, China
  • fYear
    2009
  • fDate
    26-28 Dec. 2009
  • Firstpage
    1597
  • Lastpage
    1600
  • Abstract
    The security of critical infrastructures like water, gas or power grid control systems has been discussed more thoroughly in recent years due to recent events that have questioned their security. One has to understand that, despite some systems being considered secure, attackers will continue to discover new vulnerabilities, to try new attacks and some of those attempts will succeed. One approach to address this problem that is gaining momentum recently is intrusion tolerance. Based on this paradigm, there already are intrusion-tolerant network architectures that enhance the protection of critical infrastructures. This paper justifies how we combine the concept of intrusion-tolerant with public key infrastructure(PKI) and presents some in-sights on how to do it. With the kernel of PKI, which is certificate authority, this paper brings the concept of intrusion tolerance to CA, and gives a feasible scheme of CA based on intrusion tolerance. The most important part is that it discusses the system architect, a digital signature of CA based on intrusion tolerance, and the working process of the whole system. Aiming at some shortcomings, it indicates the further work which needs to be improved in the future.
  • Keywords
    computer network security; critical infrastructures; digital signatures; public key cryptography; CA digital signature; critical infrastructures; intrusion tolerance; power grid control systems; public key infrastructure; Authentication; Computer security; Cryptography; Data security; Digital signatures; Educational institutions; Fault tolerance; Information science; Protection; Software;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Science and Engineering (ICISE), 2009 1st International Conference on
  • Conference_Location
    Nanjing
  • Print_ISBN
    978-1-4244-4909-5
  • Type

    conf

  • DOI
    10.1109/ICISE.2009.155
  • Filename
    5454490