11th Pacific Rim International Symposium on Dependable Computing (PRDC'05)
A Novel Approach to Kernel Construction of China Bridge CA
Changsha, Hunan, China
December 12-December 14
ISBN: 0-7695-2492-3
This paper gives a general overview of the current PKI interoperability efforts sighting the different interoperability models being used. It also gives a detailed analysis of the bridge certification authority (BCA), the favoured model in interoperability efforts in China. This paper presents a model used B-level lightweight security kernel (BSK) in China BCA framework. The BSK model is used to highlight kernel security level of China BCA implementation. BSK introduces security object model based three classes of objects and message dispatch model. It also presents the BSK message dispatch algorithm targeted for TCSEC class B1 or above to enforce performance adopting a route cache policy over all subjects and objects it controls.