{"id":478572,"date":"2023-08-09T09:34:59","date_gmt":"2023-08-09T09:34:59","guid":{"rendered":""},"modified":"2023-09-05T11:17:06","modified_gmt":"2023-09-05T11:17:06","slug":"public-key-infrastructure","status":"publish","type":"wiki","link":"https:\/\/oneproxy.pro\/cn\/wiki\/public-key-infrastructure\/","title":{"rendered":"\u516c\u94a5\u57fa\u7840\u8bbe\u65bd"},"content":{"rendered":"<p>\u6709\u5173\u516c\u94a5\u57fa\u7840\u8bbe\u65bd\u7684\u7b80\u8981\u4fe1\u606f<\/p>\n<p>\u516c\u94a5\u57fa\u7840\u8bbe\u65bd (PKI) \u662f\u521b\u5efa\u3001\u7ba1\u7406\u3001\u5206\u53d1\u3001\u4f7f\u7528\u3001\u5b58\u50a8\u548c\u64a4\u9500\u6570\u5b57\u8bc1\u4e66\u4ee5\u53ca\u7ba1\u7406\u516c\u94a5\u52a0\u5bc6\u6240\u9700\u7684\u4e00\u7ec4\u89d2\u8272\u3001\u7b56\u7565\u3001\u786c\u4ef6\u3001\u8f6f\u4ef6\u548c\u8fc7\u7a0b\u3002\u5b83\u5145\u5f53\u521b\u5efa\u5b89\u5168\u8fde\u63a5\u5e76\u901a\u8fc7\u6570\u5b57\u7b7e\u540d\u786e\u4fdd\u6570\u636e\u5b8c\u6574\u6027\u7684\u6846\u67b6\u3002<\/p>\n<h2>\u516c\u94a5\u57fa\u7840\u8bbe\u65bd\u7684\u8d77\u6e90\u548c\u9996\u6b21\u63d0\u53ca\u7684\u5386\u53f2<\/h2>\n<p>\u516c\u94a5\u5bc6\u7801\u5b66\u662f PKI \u7684\u57fa\u7840\u6280\u672f\uff0c\u4e8e 20 \u4e16\u7eaa 70 \u5e74\u4ee3\u521d\u9996\u6b21\u63a8\u51fa\u3002 Whitfield Diffie \u548c Martin Hellman \u5728\u5176\u53d1\u5c55\u4e2d\u53d1\u6325\u4e86\u91cd\u8981\u4f5c\u7528\uff0c\u5e76\u4e8e 1976 \u5e74\u53d1\u8868\u4e86\u4e00\u7bc7\u5173\u4e8e\u8be5\u4e3b\u9898\u7684\u5f00\u521b\u6027\u8bba\u6587\u3002RSA (Rivest\u2013Shamir\u2013Adleman) \u968f\u540e\u666e\u53ca\u4e86\u8be5\u7b97\u6cd5\uff0c\u5bfc\u81f4 PKI \u4f5c\u4e3a\u4fdd\u62a4\u6570\u5b57\u901a\u4fe1\u7684\u7efc\u5408\u7cfb\u7edf\u7684\u51fa\u73b0\u3002<\/p>\n<h2>\u6709\u5173\u516c\u94a5\u57fa\u7840\u8bbe\u65bd\u7684\u8be6\u7ec6\u4fe1\u606f<\/h2>\n<p>\u516c\u94a5\u57fa\u7840\u8bbe\u65bd\u5728\u4fdd\u62a4\u4ece\u7535\u5b50\u90ae\u4ef6\u52a0\u5bc6\u5230\u7535\u5b50\u5546\u52a1\u4ea4\u6613\u7684\u5404\u79cd\u6570\u5b57\u4ea4\u4e92\u7684\u5b89\u5168\u65b9\u9762\u53d1\u6325\u7740\u81f3\u5173\u91cd\u8981\u7684\u4f5c\u7528\u3002\u5b83\u4f7f\u7528\u4e24\u4e2a\u5bc6\u94a5\uff1a\u6bcf\u4e2a\u4eba\u90fd\u77e5\u9053\u7684\u516c\u94a5\u548c\u4fdd\u5bc6\u7684\u79c1\u94a5\u3002\u8fd9\u4e9b\u5bc6\u94a5\u7684\u7ec4\u5408\u5141\u8bb8\u5efa\u7acb\u4fe1\u4efb\u5e76\u9a8c\u8bc1\u901a\u8fc7\u7f51\u7edc\u901a\u4fe1\u7684\u5b9e\u4f53\u7684\u8eab\u4efd\u3002<\/p>\n<h3>PKI \u7684\u7ec4\u6210\u90e8\u5206\uff1a<\/h3>\n<ul>\n<li><strong>\u8bc1\u4e66\u9881\u53d1\u673a\u6784 (CA)\uff1a<\/strong> \u4ed6\u4eec\u9881\u53d1\u548c\u7ba1\u7406\u6570\u5b57\u8bc1\u4e66\u3002<\/li>\n<li><strong>\u6ce8\u518c\u673a\u6784 (RA)\uff1a<\/strong> \u4ed6\u4eec\u9a8c\u8bc1\u5e76\u6279\u51c6\u6570\u5b57\u8bc1\u4e66\u7684\u8bf7\u6c42\u3002<\/li>\n<li><strong>\u6700\u7ec8\u7528\u6237\u8ba2\u9605\u8005\uff1a<\/strong> \u4f7f\u7528\u8bc1\u4e66\u7684\u4e2a\u4eba\u6216\u7cfb\u7edf\u3002<\/li>\n<li><strong>\u9a8c\u8bc1\u670d\u52a1\u5668\uff1a<\/strong> \u4ed6\u4eec\u9a8c\u8bc1\u6570\u5b57\u8bc1\u4e66\u7684\u771f\u5b9e\u6027\u3002<\/li>\n<\/ul>\n<h2>\u516c\u94a5\u57fa\u7840\u8bbe\u65bd\u7684\u5185\u90e8\u7ed3\u6784<\/h2>\n<p>PKI\u5efa\u7acb\u5728\u5206\u5c42\u6a21\u578b\u4e4b\u4e0a\uff0c\u8bc1\u4e66\u9881\u53d1\u673a\u6784\u4f4d\u4e8e\u9876\u5c42\uff0c\u8d1f\u8d23\u7ba1\u7406\u5e76\u5411\u5176\u4ed6\u5b9e\u4f53\u9881\u53d1\u6570\u5b57\u8bc1\u4e66\u3002\u4ee5\u4e0b\u662f\u8be6\u7ec6\u6982\u8ff0\uff1a<\/p>\n<ol>\n<li><strong>\u6839 CA\uff1a<\/strong> \u8fd9\u662f\u7b7e\u7f72\u81ea\u5df1\u8bc1\u4e66\u7684\u6700\u9ad8\u6743\u5a01\u673a\u6784\u3002<\/li>\n<li><strong>\u4e2d\u7ea7CA\uff1a<\/strong> \u5b83\u4eec\u5145\u5f53\u4e2d\u4ecb\uff0c\u4ece\u6839 CA \u83b7\u53d6\u8bc1\u4e66\u5e76\u5c06\u5176\u9881\u53d1\u7ed9\u6700\u7ec8\u5b9e\u4f53\u3002<\/li>\n<li><strong>\u6700\u7ec8\u5b9e\u4f53\uff1a<\/strong> \u4f7f\u7528\u8bc1\u4e66\u8fdb\u884c\u5b89\u5168\u901a\u4fe1\u7684\u4e2a\u4eba\u6216\u7cfb\u7edf\u3002<\/li>\n<\/ol>\n<p>\u79c1\u94a5\u88ab\u5b89\u5168\u5b58\u50a8\u4e14\u6c38\u4e0d\u4f20\u8f93\uff0c\u786e\u4fdd\u4fe1\u606f\u7684\u5b8c\u6574\u6027\u548c\u673a\u5bc6\u6027\u3002<\/p>\n<h2>\u516c\u94a5\u57fa\u7840\u8bbe\u65bd\u7684\u4e3b\u8981\u7279\u5f81\u5206\u6790<\/h2>\n<p>PKI \u7684\u4e3b\u8981\u7279\u70b9\u5305\u62ec\uff1a<\/p>\n<ul>\n<li><strong>\u9a8c\u8bc1\uff1a<\/strong> \u9a8c\u8bc1\u901a\u4fe1\u53cc\u65b9\u7684\u8eab\u4efd\u3002<\/li>\n<li><strong>\u6b63\u76f4\uff1a<\/strong> \u786e\u4fdd\u6570\u636e\u672a\u88ab\u66f4\u6539\u3002<\/li>\n<li><strong>\u4fdd\u5bc6\uff1a<\/strong> \u52a0\u5bc6\u6570\u636e\u4ee5\u4fdd\u8bc1\u5176\u673a\u5bc6\u6027\u3002<\/li>\n<li><strong>\u4e0d\u53ef\u5426\u8ba4\u6027\uff1a<\/strong> \u9632\u6b62\u5b9e\u4f53\u5426\u8ba4\u5176\u53c2\u4e0e\u4ea4\u6613\u3002<\/li>\n<li><strong>\u53ef\u6269\u5c55\u6027\uff1a<\/strong> \u53ef\u4ee5\u6269\u5c55\u4ee5\u5305\u542b\u66f4\u591a\u7528\u6237\u6216\u7cfb\u7edf\u3002<\/li>\n<\/ul>\n<h2>\u516c\u94a5\u57fa\u7840\u8bbe\u65bd\u7684\u7c7b\u578b<\/h2>\n<p>PKI \u4e3b\u8981\u6709\u4e24\u79cd\u7c7b\u578b\uff1a<\/p>\n<ol>\n<li><strong>\u516c\u5171\u516c\u94a5\u57fa\u7840\u8bbe\u65bd\uff1a<\/strong> \u7531\u516c\u4f17\u4fe1\u4efb\u7684 CA \u7ba1\u7406\uff0c\u5411\u6240\u6709\u4eba\u5f00\u653e\u3002<\/li>\n<li><strong>\u79c1\u4eba\u516c\u94a5\u57fa\u7840\u8bbe\u65bd\uff1a<\/strong> \u5728\u7ec4\u7ec7\u5185\u7ba1\u7406\uff0c\u7528\u4e8e\u5185\u90e8\u76ee\u7684\u3002<\/li>\n<\/ol>\n<table>\n<thead>\n<tr>\n<th>\u7c7b\u578b<\/th>\n<th>\u516c\u5171\u516c\u94a5\u57fa\u7840\u8bbe\u65bd<\/th>\n<th>\u79c1\u6709\u516c\u94a5\u57fa\u7840\u8bbe\u65bd<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>\u65e0\u969c\u788d<\/td>\n<td>\u5411\u6240\u6709\u4eba\u5f00\u653e<\/td>\n<td>\u53d7\u9650\u5236\u7684<\/td>\n<\/tr>\n<tr>\n<td>\u4f7f\u7528\u6848\u4f8b<\/td>\n<td>\u4e92\u8054\u7f51<\/td>\n<td>\u5185\u8054\u7f51<\/td>\n<\/tr>\n<tr>\n<td>\u4fe1\u4efb\u7ea7\u522b<\/td>\n<td>\u5e7f\u6cdb\u7684\u4fe1\u4efb<\/td>\n<td>\u5185\u90e8\u4fe1\u4efb<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>\u516c\u94a5\u57fa\u7840\u8bbe\u65bd\u7684\u4f7f\u7528\u65b9\u6cd5\u3001\u95ee\u9898\u53ca\u5176\u89e3\u51b3\u65b9\u6848<\/h2>\n<h3>\u4f7f\u7528\u65b9\u6cd5\uff1a<\/h3>\n<ul>\n<li><strong>\u5b89\u5168\u7535\u5b50\u90ae\u4ef6\u901a\u4fe1<\/strong><\/li>\n<li><strong>\u6570\u5b57\u7b7e\u540d<\/strong><\/li>\n<li><strong>\u5b89\u5168\u7684\u7f51\u7edc\u6d4f\u89c8<\/strong><\/li>\n<\/ul>\n<h3>\u95ee\u9898\uff1a<\/h3>\n<ul>\n<li><strong>\u5bc6\u94a5\u7ba1\u7406\uff1a<\/strong> \u96be\u4ee5\u7ba1\u7406\u3002<\/li>\n<li><strong>\u6210\u672c\uff1a<\/strong> \u521d\u59cb\u8bbe\u7f6e\u6210\u672c\u9ad8\u3002<\/li>\n<li><strong>\u590d\u6742\uff1a<\/strong> \u9700\u8981\u4e13\u4e1a\u77e5\u8bc6\u6765\u5b9e\u65bd\u3002<\/li>\n<\/ul>\n<h3>\u89e3\u51b3\u65b9\u6848\uff1a<\/h3>\n<ul>\n<li><strong>\u6258\u7ba1 PKI \u670d\u52a1\uff1a<\/strong> \u5c06\u7ba1\u7406\u5916\u5305\u7ed9\u4e13\u4e1a\u4eba\u5458\u3002<\/li>\n<li><strong>\u81ea\u52a8\u5316\u5de5\u5177\uff1a<\/strong> \u7b80\u5316\u5bc6\u94a5\u7ba1\u7406\u6d41\u7a0b\u3002<\/li>\n<\/ul>\n<h2>\u4e3b\u8981\u7279\u70b9\u53ca\u5176\u4ed6\u4e0e\u540c\u7c7b\u4ea7\u54c1\u7684\u6bd4\u8f83<\/h2>\n<table>\n<thead>\n<tr>\n<th>\u5b66\u671f<\/th>\n<th>\u516c\u94a5\u57fa\u7840\u8bbe\u65bd<\/th>\n<th>SSL\/TLS<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>\u9a8c\u8bc1<\/td>\n<td>\u53cc\u5411<\/td>\n<td>\u5927\u591a\u662f\u5355\u5411\u7684<\/td>\n<\/tr>\n<tr>\n<td>\u52a0\u5bc6\u5bc6\u94a5<\/td>\n<td>\u516c\u94a5\u548c\u79c1\u94a5<\/td>\n<td>\u5bf9\u79f0\u5bc6\u94a5<\/td>\n<\/tr>\n<tr>\n<td>\u4f7f\u7528<\/td>\n<td>\u5404\u79cd\uff08\u7535\u5b50\u90ae\u4ef6\u3001VPN \u7b49\uff09<\/td>\n<td>\u4e3b\u8981\u662f\u7f51\u7edc\u6d4f\u89c8\u5668<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>\u4e0e\u516c\u94a5\u57fa\u7840\u8bbe\u65bd\u76f8\u5173\u7684\u672a\u6765\u524d\u666f\u548c\u6280\u672f<\/h2>\n<p>\u91cf\u5b50\u8ba1\u7b97\u7b49\u65b0\u5174\u6280\u672f\u7ed9 PKI \u5e26\u6765\u4e86\u65b0\u7684\u6311\u6218\uff0c\u9700\u8981\u7b97\u6cd5\u548c\u7cfb\u7edf\u7684\u521b\u65b0\u3002\u533a\u5757\u94fe\u53ef\u4ee5\u63d0\u4f9b\u53bb\u4e2d\u5fc3\u5316\u7684\u4fe1\u4efb\u6a21\u578b\uff0c\u800c\u4eba\u5de5\u667a\u80fd\u53ef\u4ee5\u81ea\u52a8\u5316\u8bb8\u591a PKI \u6d41\u7a0b\u3002<\/p>\n<h2>\u5982\u4f55\u4f7f\u7528\u4ee3\u7406\u670d\u52a1\u5668\u6216\u5982\u4f55\u5c06\u4ee3\u7406\u670d\u52a1\u5668\u4e0e\u516c\u94a5\u57fa\u7840\u8bbe\u65bd\u5173\u8054<\/h2>\n<p>\u4ee3\u7406\u670d\u52a1\u5668\uff08\u4f8b\u5982 OneProxy \u63d0\u4f9b\u7684\u4ee3\u7406\u670d\u52a1\u5668\uff09\u53ef\u4ee5\u5229\u7528 PKI \u6765\u6dfb\u52a0\u989d\u5916\u7684\u5b89\u5168\u548c\u9690\u79c1\u5c42\u3002\u901a\u8fc7\u5229\u7528\u6570\u5b57\u8bc1\u4e66\uff0c\u4ee3\u7406\u670d\u52a1\u5668\u53ef\u4ee5\u5bf9\u5ba2\u6237\u7aef\u548c\u670d\u52a1\u5668\u4e4b\u95f4\u7684\u901a\u4fe1\u8fdb\u884c\u8eab\u4efd\u9a8c\u8bc1\u548c\u52a0\u5bc6\uff0c\u4ece\u800c\u786e\u4fdd\u6570\u636e\u7684\u9690\u79c1\u6027\u548c\u5b8c\u6574\u6027\u3002<\/p>\n<h2>\u76f8\u5173\u94fe\u63a5<\/h2>\n<ul>\n<li><a href=\"https:\/\/www.openssl.org\/\" target=\"_new\" rel=\"noopener nofollow\">OpenSSL \u9879\u76ee<\/a><\/li>\n<li><a href=\"https:\/\/datatracker.ietf.org\/wg\/pkix\/about\/\" target=\"_new\" rel=\"noopener nofollow\">IETF PKI \u5de5\u4f5c\u7ec4<\/a><\/li>\n<li><a href=\"https:\/\/oneproxy.pro\/cn\/\" target=\"_new\" rel=\"noopener\">OneProxy\u670d\u52a1<\/a><\/li>\n<\/ul>\n<p>\u516c\u94a5\u57fa\u7840\u8bbe\u65bd\u7684\u7406\u89e3\u548c\u5b9e\u65bd\u5bf9\u4e8e\u5f53\u4eca\u4e92\u8054\u4e16\u754c\u7684\u6570\u5b57\u5b89\u5168\u4ecd\u7136\u81f3\u5173\u91cd\u8981\u3002\u6b63\u786e\u4f7f\u7528\u5b83\u53ef\u4ee5\u786e\u4fdd\u5b89\u5168\u548c\u53ef\u4fe1\u7684\u901a\u4fe1\uff0c\u6ee1\u8db3\u4e2a\u4eba\u548c\u7ec4\u7ec7\u7684\u5b89\u5168\u9700\u6c42\u3002<\/p>","protected":false},"featured_media":478573,"menu_order":0,"template":"","meta":{"_acf_changed":false,"content-type":"","inline_featured_image":false,"footnotes":""},"class_list":["post-478572","wiki","type-wiki","status-publish","has-post-thumbnail","hentry"],"acf":{"faq_title":"Frequently Asked Questions about <mark>Public Key Infrastructure (PKI)<\/mark>","faq_items":[{"question":"What is Public Key Infrastructure (PKI)?","answer":"<p>Public Key Infrastructure (PKI) is a framework that includes roles, policies, hardware, software, and procedures needed to create, manage, distribute, use, store, and revoke digital certificates. It manages public-key encryption and ensures secure connections and data integrity.<\/p>"},{"question":"Who were the pioneers in the development of Public Key Infrastructure?","answer":"<p>Whitfield Diffie and Martin Hellman were instrumental in the development of public key cryptography in the early 1970s. RSA then popularized the algorithms, leading to the emergence of PKI.<\/p>"},{"question":"What are the main components of Public Key Infrastructure?","answer":"<p>The main components of PKI include Certificate Authorities (CAs), Registration Authorities (RAs), End-User Subscribers, and Validation Servers. CAs issue and manage digital certificates, RAs verify requests for certificates, and End-User Subscribers use the certificates.<\/p>"},{"question":"How does Public Key Infrastructure work?","answer":"<p>PKI uses a combination of public and private keys to establish trust and verify the identity of entities communicating over a network. The hierarchical structure consists of the Root CA at the top, Intermediate CAs, and End Entities, ensuring integrity and confidentiality.<\/p>"},{"question":"What are the key features of Public Key Infrastructure?","answer":"<p>The key features of PKI include authentication, integrity, confidentiality, non-repudiation, and scalability. These features help in verifying identity, ensuring data integrity, encrypting data, and expanding to include more users.<\/p>"},{"question":"What are the types of Public Key Infrastructure?","answer":"<p>There are two main types of PKI: Public PKI, which is managed by a publicly trusted CA and open to everyone, and Private PKI, which is managed within an organization and used for internal purposes.<\/p>"},{"question":"What are the common problems with Public Key Infrastructure, and how can they be solved?","answer":"<p>Common problems with PKI include difficulties with key management, high initial setup cost, and complexity in implementation. Solutions can include Managed PKI Services, outsourcing to professionals, and using automated tools to ease key management.<\/p>"},{"question":"How are proxy servers like OneProxy associated with Public Key Infrastructure?","answer":"<p>Proxy servers like OneProxy can utilize PKI to authenticate and encrypt communications between clients and servers. This adds an additional layer of security and privacy, ensuring data privacy and integrity.<\/p>"},{"question":"What are the future perspectives and technologies related to Public Key Infrastructure?","answer":"<p>Emerging technologies like Quantum Computing, Blockchain, and Artificial Intelligence pose new challenges and opportunities for PKI. Quantum Computing requires innovation in algorithms, while Blockchain may offer decentralized trust models, and AI can automate many PKI processes.<\/p>"},{"question":"Where can I find more information about Public Key Infrastructure?","answer":"<p>You can find more detailed information about Public Key Infrastructure by visiting resources like the <a href=\"https:\/\/www.openssl.org\/\" target=\"_new\">OpenSSL Project<\/a>, the <a href=\"https:\/\/datatracker.ietf.org\/wg\/pkix\/about\/\" target=\"_new\">IETF PKI Working Group<\/a>, and <a href=\"https:\/\/oneproxy.pro\" target=\"_new\">OneProxy Services<\/a>.<\/p>"}]},"_links":{"self":[{"href":"https:\/\/oneproxy.pro\/cn\/wp-json\/wp\/v2\/wiki\/478572","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/oneproxy.pro\/cn\/wp-json\/wp\/v2\/wiki"}],"about":[{"href":"https:\/\/oneproxy.pro\/cn\/wp-json\/wp\/v2\/types\/wiki"}],"version-history":[{"count":0,"href":"https:\/\/oneproxy.pro\/cn\/wp-json\/wp\/v2\/wiki\/478572\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/oneproxy.pro\/cn\/wp-json\/wp\/v2\/media\/478573"}],"wp:attachment":[{"href":"https:\/\/oneproxy.pro\/cn\/wp-json\/wp\/v2\/media?parent=478572"}],"curies":[{"name":"\u53ef\u6e7f\u6027\u7c89\u5242","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}