Efficient offline certificate revocation

被引:0
|
作者
Muñoz, JL
Forné, J
Esparza, O
Soriano, M
机构
来源
INTERACTIVE MULTIMEDIA ON NEXT GENERATION NETWORKS | 2003年 / 2899卷
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Identity Certificates (ICs) are widely used as underlying technology for securing many protocols and applications in the Internet. A Public Key Infrastructure (PKI) is required to securely deliver these certificates to widely-distributed users or systems. An identity certificate contains credentials and statements and as an document of this kind its contents are only guaranteed for a limited amount of time. The validity period of an IC might be quite long (up to several years). However, there are circumstances under which the validity of a certificate must be terminated sooner than assigned and thus, the certificate needs to be revoked. The revocation of certificates implies one of the major scalability problems in the whole PKI. Revocation can be achieved using either an online scheme or an offline scheme. In this paper we introduce the basics of these two schemes and we dicuss their advantages and drawbacks. We show also that offline systems provide the best level of security protection. Finally, we present an efficient offline system with bandwidth requirements similar to typical online systems.
引用
收藏
页码:319 / 330
页数:12
相关论文
共 50 条
  • [21] Performance optimizations for certificate revocation
    Li, BH
    Zhao, YL
    Hou, YB
    2004 IEEE Workshop on IP Operations and Management Proceedings (IPOM 2004): SELF-MEASUREMENT & SELF-MANAGEMENT OF IP NETWORKS & SERVICES, 2004, : 94 - 97
  • [22] Tradeoffs in certificate revocation schemes
    Zheng, PF
    ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2003, 33 (02) : 103 - 112
  • [23] A scalable scheme for certificate revocation
    Li, BH
    Hou, YB
    Zhao, YL
    Proceedings of 2005 International Conference on Machine Learning and Cybernetics, Vols 1-9, 2005, : 3852 - 3856
  • [24] Design of a certificate revocation platform
    Muñoz, JL
    Forné, J
    ITRE2003: INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY: RESEARCH AND EDUCATION, 2003, : 259 - 263
  • [25] Separable implicit certificate revocation
    Yum, DH
    Lee, PJ
    INFORMATION SECURITY AND CRYPTOLOGY - ICISC 2004, 2004, 3506 : 121 - 136
  • [26] Certificate-based encryption and the certificate revocation problem
    Gentry, C
    ADVANCES IN CRYPTOLOGY-EUROCRYPT 2003, 2003, 2656 : 272 - 293
  • [27] Augmented certificate revocation lists
    Lakshminarayanan, A.
    Lim, T. L.
    INFORMATION SECURITY AND PRIVACY, PROCEEDINGS, 2006, 4058 : 87 - 98
  • [28] On the Probability of Certificate Revocation in Combinatorial Certificate Management Schemes
    Yum, Dae Hyun
    IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2015, E98D (05): : 1104 - 1107
  • [29] Efficient Management of Certificate Revocation Lists in Smart Grid Advanced Metering Infrastructure
    Cebe, Mumin
    Akkaya, Kemal
    2017 IEEE 14TH INTERNATIONAL CONFERENCE ON MOBILE AD HOC AND SENSOR SYSTEMS (MASS), 2017, : 313 - 317
  • [30] SECRET: A Secure and Efficient Certificate Revocation Scheme for Mobile Ad Hoc Networks
    Mall, Dieynaba
    Konate, Karim
    Pathan, Al-Sakib Khan
    2014 INTERNATIONAL SYMPOSIUM ON BIOMETRICS AND SECURITY TECHNOLOGIES (ISBAST), 2014, : 137 - 143