BRT: An Efficient and Scalable Blockchain-Based Revocation Transparency System for TLS Connections

被引:0
|
作者
Xing, Qianqian [1 ]
Wang, Xiaofeng [1 ]
Xu, Xinyue [1 ]
Lin, Jiaqi [2 ]
Wang, Fei [1 ]
Li, Cui [1 ]
Wang, Baosheng [1 ]
机构
[1] Natl Univ Def Technol, Coll Comp, Changsha 410073, Peoples R China
[2] Inst Syst Engn AMS PLA, Beijing 100039, Peoples R China
基金
国家重点研发计划; 中国国家自然科学基金;
关键词
PKI and TLS security; revocation; blockchain;
D O I
10.3390/s23218816
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
Log-based public key infrastructure(PKI) refers to a robust class of CA-attack-resilient PKI that enhance transparency and accountability in the certificate revocation and issuance process by compelling certificate authorities (CAs) to submit revocations to publicly and verifiably accessible logs. However, log-based PKIs suffer from a reliance on centralized and consistent sources of information, rendering them susceptible to split-world attacks, and they regrettably fail to provide adequate incentives for recording or monitoring CA behavior. Blockchain-based PKIs address these limitations by enabling decentralized log audits through automated financial incentives. However, they continue to face challenges in developing a scalable revocation mechanism suited for lightweight clients. In this paper, we introduce BRT, a scalable blockchain-based system for certificate and revocation transparency. It serves to log, audit, and validate the status of certificates within the transport layer security (TLS)/secure sockets layer(SSL) PKI domain. We designed an audit-on-chain framework, coupled with an off-chain storage/computation system, to enhance the efficiency of BRT when operating in a blockchain environment. By implementing a blockchain-based prototype, we demonstrate that BRT achieves storage-efficient log recording with a peak compression rate reaching 8%, cost-effective log updates for large-scale certificates, and near-instantaneous revocation checks for users.
引用
收藏
页数:23
相关论文
共 50 条
  • [1] Blockchain-Based Certificate Transparency and Revocation Transparency
    Wang, Ze
    Lin, Jingqiang
    Cai, Quanwei
    Wang, Qiongxiao
    Zha, Daren
    Jing, Jiwu
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2022, 19 (01) : 681 - 697
  • [2] Private Status Retrieval for Blockchain-based Certificate Revocation System
    Ruan, Zhichao
    Ye, Wei
    Xie, Yankai
    Li, Haixing
    Zhang, Chi
    Wei, Lingbo
    ICC 2023-IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, 2023, : 6565 - 6570
  • [3] A blockchain-based certificate revocation management and status verification system
    Adja, Yves Christian Elloh
    Hammi, Badis
    Serhrouchni, Ahmed
    Zeadally, Sherali
    COMPUTERS & SECURITY, 2021, 104
  • [4] CertChain: Public and Efficient Certificate Audit Based on Blockchain for TLS Connections
    Chen, Jing
    Yao, Shixiong
    Yuan, Quan
    He, Kun
    Ji, Shouling
    Du, Ruiying
    IEEE CONFERENCE ON COMPUTER COMMUNICATIONS (IEEE INFOCOM 2018), 2018, : 2069 - 2077
  • [5] PADVA: A Blockchain-based TLS Notary Service
    Szalachowski, Pawel
    2019 IEEE 25TH INTERNATIONAL CONFERENCE ON PARALLEL AND DISTRIBUTED SYSTEMS (ICPADS), 2019, : 836 - 843
  • [6] Efficient Message Authentication with Revocation Transparency Using Blockchain for Vehicular Networks
    Li, Kang
    Lau, Wang Fat
    Au, Man Ho
    Ho, Ivan Wang-Hei
    Wang, Yilei
    COMPUTERS & ELECTRICAL ENGINEERING, 2020, 86
  • [7] An efficient blockchain-based anonymous authentication and supervision system
    Weiyou Liang
    Yujue Wang
    Yong Ding
    Haibin Zheng
    Hai Liang
    Huiyong Wang
    Peer-to-Peer Networking and Applications, 2023, 16 : 2492 - 2511
  • [8] Bitforest: a Portable and Efficient Blockchain-Based Naming System
    Dong, Yuhao
    Kim, Woojung
    Boutaba, Raouf
    2018 14TH INTERNATIONAL CONFERENCE ON NETWORK AND SERVICE MANAGEMENT (CNSM), 2018, : 226 - 232
  • [9] Blockchain-Based Data Transparency: Issues and Challenges
    Meng X.
    Liu L.
    Liu, Lixin (99liulixin@163.com), 1600, Science Press (58): : 237 - 252
  • [10] A blockchain-based traceability system with efficient search and query
    Chengzhe Lai
    Yinzhen Wang
    Hong Wang
    Dong Zheng
    Peer-to-Peer Networking and Applications, 2023, 16 : 675 - 689