BRT: An Efficient and Scalable Blockchain-Based Revocation Transparency System for TLS Connections

被引:0
|
作者
Xing, Qianqian [1 ]
Wang, Xiaofeng [1 ]
Xu, Xinyue [1 ]
Lin, Jiaqi [2 ]
Wang, Fei [1 ]
Li, Cui [1 ]
Wang, Baosheng [1 ]
机构
[1] Natl Univ Def Technol, Coll Comp, Changsha 410073, Peoples R China
[2] Inst Syst Engn AMS PLA, Beijing 100039, Peoples R China
基金
国家重点研发计划; 中国国家自然科学基金;
关键词
PKI and TLS security; revocation; blockchain;
D O I
10.3390/s23218816
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
Log-based public key infrastructure(PKI) refers to a robust class of CA-attack-resilient PKI that enhance transparency and accountability in the certificate revocation and issuance process by compelling certificate authorities (CAs) to submit revocations to publicly and verifiably accessible logs. However, log-based PKIs suffer from a reliance on centralized and consistent sources of information, rendering them susceptible to split-world attacks, and they regrettably fail to provide adequate incentives for recording or monitoring CA behavior. Blockchain-based PKIs address these limitations by enabling decentralized log audits through automated financial incentives. However, they continue to face challenges in developing a scalable revocation mechanism suited for lightweight clients. In this paper, we introduce BRT, a scalable blockchain-based system for certificate and revocation transparency. It serves to log, audit, and validate the status of certificates within the transport layer security (TLS)/secure sockets layer(SSL) PKI domain. We designed an audit-on-chain framework, coupled with an off-chain storage/computation system, to enhance the efficiency of BRT when operating in a blockchain environment. By implementing a blockchain-based prototype, we demonstrate that BRT achieves storage-efficient log recording with a peak compression rate reaching 8%, cost-effective log updates for large-scale certificates, and near-instantaneous revocation checks for users.
引用
收藏
页数:23
相关论文
共 50 条
  • [41] BPKI: A secure and scalable blockchain-based public key infrastructure system for web services
    Zhai, Zhonghao
    Shen, Subin
    Mao, Yanqin
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2022, 68
  • [42] Blockchain-Based Efficient Incentive Mechanism in Crowdsensing
    Jiang, Qiulu
    Wan, Wunan
    Qin, Zhi
    Zhang, Jinquan
    Han, Hui
    Zhang, Shibin
    Xia, Jinyue
    ARTIFICIAL INTELLIGENCE AND SECURITY, ICAIS 2022, PT III, 2022, 13340 : 120 - 132
  • [43] An Efficient and Decentralized Blockchain-based Commercial Alternative
    Zeggari, Marwan
    Lambiotte, Renaud
    Abadi, Aydin
    Kassab, Mohamad
    2023 IEEE 20TH INTERNATIONAL CONFERENCE ON SOFTWARE ARCHITECTURE COMPANION, ICSA-C, 2023, : 231 - 238
  • [44] Efficient Blockchain-Based Pseudonym Authentication Scheme Supporting Revocation for 5G-Assisted Vehicular Fog Computing
    Mohammed, Badiea Abdulkarem
    Al-Shareeda, Mahmood A.
    Alsadhan, Abeer Abdullah
    Al-Mekhlafi, Zeyad Ghaleb
    Sallam, Amer A.
    Al-Qatab, Bassam Ali
    Alshammari, Mohammad T.
    Alayba, Abdulaziz M.
    IEEE ACCESS, 2024, 12 : 33089 - 33099
  • [45] Blockchain-based efficient communication for food supply chain industry: Transparency and traceability analysis for sustainable business
    Tayal, Akash
    Solanki, Arun
    Kondal, Richa
    Nayyar, Anand
    Tanwar, Sudeep
    Kumar, Neeraj
    INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2021, 34 (04)
  • [46] BlockTrail: A Scalable Multichain Solution for Blockchain-based Audit Trails
    Ahmad, Ashar
    Saad, Muhammad
    Njilla, Laurent
    Kamhoua, Charles
    Bassiouni, Mostafa
    Mohaisen, Aziz
    ICC 2019 - 2019 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2019,
  • [47] FlyTrap: A Blockchain-based Proxy for Authorisation and Audit of MQTT Connections
    Dryja, Konrad M.
    Markovic, Milan
    Edwards, Peter
    2021 EIGHTH INTERNATIONAL CONFERENCE ON INTERNET OF THINGS, SYSTEMS, MANAGEMENT AND SECURITY (IOTSMS), 2021, : 98 - 105
  • [48] An efficient blockchain-based framework for file sharing
    Peng, Wanzong
    Lu, Tongliang
    Peng, Wenju
    Wang, Zhongpan
    SCIENTIFIC REPORTS, 2024, 14 (01):
  • [49] A Scalable Blockchain-Based Trust Management Strategy for Vehicular Networks
    Li, Minghao
    Zhao, Gansen
    Lai, Ruilin
    WIRELESS ALGORITHMS, SYSTEMS, AND APPLICATIONS, PT III, 2022, 13473 : 285 - 295
  • [50] Flexible and Efficient Blockchain-Based Cloud Storage
    Pan, Ying-yu
    Li, Yi
    Gao, Ce-yu
    Fang, Li
    Chen, Ping
    2021 IEEE 14TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING (CLOUD 2021), 2021, : 304 - 312