Efficient offline certificate revocation

被引:0
|
作者
Muñoz, JL
Forné, J
Esparza, O
Soriano, M
机构
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Identity Certificates (ICs) are widely used as underlying technology for securing many protocols and applications in the Internet. A Public Key Infrastructure (PKI) is required to securely deliver these certificates to widely-distributed users or systems. An identity certificate contains credentials and statements and as an document of this kind its contents are only guaranteed for a limited amount of time. The validity period of an IC might be quite long (up to several years). However, there are circumstances under which the validity of a certificate must be terminated sooner than assigned and thus, the certificate needs to be revoked. The revocation of certificates implies one of the major scalability problems in the whole PKI. Revocation can be achieved using either an online scheme or an offline scheme. In this paper we introduce the basics of these two schemes and we dicuss their advantages and drawbacks. We show also that offline systems provide the best level of security protection. Finally, we present an efficient offline system with bandwidth requirements similar to typical online systems.
引用
收藏
页码:319 / 330
页数:12
相关论文
共 50 条
  • [1] Certificate Revocation Guard (CRG): An Efficient Mechanism for Checking Certificate Revocation
    Hu, Qinwen
    Asghar, Muhammad Rizwan
    Brownlee, Nevil
    2016 IEEE 41ST CONFERENCE ON LOCAL COMPUTER NETWORKS (LCN), 2016, : 527 - 530
  • [2] QuasiModo: Efficient certificate validation and revocation
    Elwailly, FF
    Gentry, C
    Ramzan, Z
    PUBLIC KEY CRYPTOGRAPHY - PKC 2004, PROCEEDINGS, 2004, 2947 : 375 - 388
  • [3] Efficient certificate revocation in vehicular communication
    Falk, Rainer
    Kohlmayer, Florian
    VDI Berichte, 2007, (2016): : 239 - 254
  • [4] Efficient certificate revocation in vehicular communication
    Falk, Rainer
    Kohlmayer, Florian
    AUTOMOTIVE SECURITY, 2007, 2016 : 239 - 254
  • [5] Efficient Certificate Revocation List Organization and Distribution
    Haas, Jason J.
    Hu, Yih-Chun
    Laberteaux, Kenneth P.
    IEEE JOURNAL ON SELECTED AREAS IN COMMUNICATIONS, 2011, 29 (03) : 595 - 604
  • [6] Implementation of an efficient authenticated dictionary for certificate revocation
    Muñoz, JL
    Forné, J
    Esparza, O
    Soriano, N
    EIGHTH IEEE INTERNATIONAL SYMPOSIUM ON COMPUTERS AND COMMUNICATION, VOLS I AND II, PROCEEDINGS, 2003, : 238 - 243
  • [7] Certificate revocation and certificate update
    Naor, M
    Nissim, K
    IEEE JOURNAL ON SELECTED AREAS IN COMMUNICATIONS, 2000, 18 (04) : 561 - 570
  • [8] Certificate revocation and certificate update
    Naor, M
    Nissim, K
    PROCEEDINGS OF THE SEVENTH USENIX SECURITY SYMPOSIUM, 1998, : 217 - 228
  • [9] Flexible Certificate Revocation List for Efficient Authentication in IoT
    Duan, Li
    Li, Yong
    Liao, Lijun
    PROCEEDINGS OF THE 8TH INTERNATIONAL CONFERENCE ON THE INTERNET OF THINGS (IOT'18), 2018,
  • [10] CRchain: An Efficient Certificate Revocation Scheme Based on Blockchain
    Ge, Xiaoxue
    Wang, Liming
    An, Wei
    Zhou, Xiaojun
    Li, Benyu
    ALGORITHMS AND ARCHITECTURES FOR PARALLEL PROCESSING, ICA3PP 2021, PT II, 2022, 13156 : 453 - 472