Efficient offline certificate revocation

被引:0
|
作者
Muñoz, JL
Forné, J
Esparza, O
Soriano, M
机构
来源
INTERACTIVE MULTIMEDIA ON NEXT GENERATION NETWORKS | 2003年 / 2899卷
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Identity Certificates (ICs) are widely used as underlying technology for securing many protocols and applications in the Internet. A Public Key Infrastructure (PKI) is required to securely deliver these certificates to widely-distributed users or systems. An identity certificate contains credentials and statements and as an document of this kind its contents are only guaranteed for a limited amount of time. The validity period of an IC might be quite long (up to several years). However, there are circumstances under which the validity of a certificate must be terminated sooner than assigned and thus, the certificate needs to be revoked. The revocation of certificates implies one of the major scalability problems in the whole PKI. Revocation can be achieved using either an online scheme or an offline scheme. In this paper we introduce the basics of these two schemes and we dicuss their advantages and drawbacks. We show also that offline systems provide the best level of security protection. Finally, we present an efficient offline system with bandwidth requirements similar to typical online systems.
引用
收藏
页码:319 / 330
页数:12
相关论文
共 50 条
  • [41] Communication-efficient certificate revocation management for Advanced Metering Infrastructure and IoT Integration
    Cebe, Mumin
    Akkaya, Kemal
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2021, 115 : 267 - 278
  • [42] Energy Efficient Clustering for Certificate Revocation Scheme in Mobile Ad-Hoc Network
    Rajkumar, K.
    Jeyakumar, M. K.
    WIRELESS PERSONAL COMMUNICATIONS, 2021, 118 (01) : 647 - 662
  • [43] Energy Efficient Clustering for Certificate Revocation Scheme in Mobile Ad-Hoc Network
    K. Rajkumar
    M. K. Jeyakumar
    Wireless Personal Communications, 2021, 118 : 647 - 662
  • [44] A test-bed for certificate revocation policies
    Muñoz, JL
    Forné, J
    Esparza, O
    Soriano, N
    2003 IEEE PACIFIC RIM CONFERENCE ON COMMUNICATIONS, COMPUTERS, AND SIGNAL PROCESSING, VOLS 1 AND 2, CONFERENCE PROCEEDINGS, 2003, : 561 - 564
  • [45] Certificate Revocation Schemes in Vehicular Networks: A Survey
    Wang, Qianpeng
    Gao, Deyun
    Chen, Du
    IEEE ACCESS, 2020, 8 : 26223 - 26234
  • [46] Scheme for certificate revocation using random treaps
    Cheng, Li
    Lu, Zhengding
    Li, Juan
    Huazhong Keji Daxue Xuebao (Ziran Kexue Ban)/Journal of Huazhong University of Science and Technology (Natural Science Edition), 2002, 30 (09):
  • [47] Investigate and Improve the Certificate Revocation in Web PKI
    Zhang, Chengyuan
    An, Changqing
    Yu, Tao
    Zheng, Zhiyan
    Wang, Jilong
    PROCEEDINGS OF 2024 IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM, NOMS 2024, 2024,
  • [48] Instant certificate revocation and publication using WebDAV
    Chadwick, David
    Antony, Sean
    Bjerk, Rune
    JOURNAL OF COMPUTER SECURITY, 2010, 18 (03) : 475 - 496
  • [49] Reducing certificate revocation cost using NPKI
    Levi, A
    Koç, CK
    TRUSTED INFORMATION: THE NEW DECADE CHALLENGE, 2001, 65 : 51 - 59
  • [50] Security Certificate Revocation List Distribution for VANET
    Laberteaux, Kenneth R.
    Haas, Jason J.
    Hu, Yih-Chun
    VANET'08: PROCEEDINGS OF THE FIFTH ACM INTERNATIONAL WORKSHOP ON VEHICULAR INTER-NETWORKING, 2008, : 88 - 89