CR-BA: Public Key Infrastructure Certificate Revocation Scheme Based on Blockchain and Accumulator

被引:0
|
作者
Xie, Jingxue [1 ]
Tan, Xinghong [1 ]
Tan, Liang [1 ,2 ]
机构
[1] Sichuan Normal Univ, Sch Comp Sci, Chengdu 610000, Sichuan, Peoples R China
[2] Chinese Acad Sci, Inst Comp Sci, Beijing 100000, Peoples R China
基金
中国国家自然科学基金;
关键词
D O I
10.1155/2022/2069195
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
With the development of blockchain, many studies apply blockchain to certificate revocation. However, existing blockchain-based certificate revocation schemes have two shortcomings. First, the storage overhead on the blockchain is relatively large. Second, as the number of revoked certificates increases, the misjudgment rate of certificate status will increase accordingly, so a public key infrastructure implementation certificate revocation scheme based on blockchain and accumulators, called CR-BA, is proposed. First, CR-BA expands the certificate structure, adding a revocation factor and a smart contract account for accessing the blockchain in the certificate extension, which is filled by the CA when the certificate is generated. Then, when the certificate is to be revoked, CA generates the revocation fingerprint through the revocation factor and publishes it to the blockchain. Finally, when the user needs to verify the status of the certificate, CA calculates the revocation fingerprint according to the revocation factor on the certificate, then compares it with the existing revocation fingerprint on the blockchain, and returns the comparison result to the user. The experimental results show that this scheme can effectively overcome the storage and misjudgment problems caused by existing blockchain-based certificate revocation schemes and improve the query efficiency of certificate revocation information.
引用
收藏
页数:15
相关论文
共 50 条
  • [1] CRchain: An Efficient Certificate Revocation Scheme Based on Blockchain
    Ge, Xiaoxue
    Wang, Liming
    An, Wei
    Zhou, Xiaojun
    Li, Benyu
    [J]. ALGORITHMS AND ARCHITECTURES FOR PARALLEL PROCESSING, ICA3PP 2021, PT II, 2022, 13156 : 453 - 472
  • [2] A blockchain based certificate revocation scheme for vehicular communication systems
    Lei, Ao
    Cao, Yue
    Bao, Shihan
    Li, Dasen
    Asuquo, Philip
    Cruickshank, Haitham
    Sun, Zhili
    [J]. FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2020, 110 : 892 - 903
  • [3] A Survey on X.509 Public-Key Infrastructure, Certificate Revocation, and Their Modern Implementation on Blockchain and Ledger Technologies
    Khan, Salabat
    Luo, Fei
    Zhang, Zijian
    Ullah, Farhan
    Amin, Farhan
    Qadri, Syed Furqan
    Bin Heyat, Md Belal
    Ruby, Rukhsana
    Wang, Lu
    Ullah, Shamsher
    Li, Meng
    Leung, Victor C. M.
    Wu, Kaishun
    [J]. IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2023, 25 (04): : 2529 - 2568
  • [4] Reducing certificate revocation and non-repudiation service in public key infrastructure
    Sameshima, Y
    Tsutsumi, T
    [J]. IEICE TRANSACTIONS ON FUNDAMENTALS OF ELECTRONICS COMMUNICATIONS AND COMPUTER SCIENCES, 2000, E83A (07) : 1441 - 1449
  • [6] An agent based certificate revocation scheme for public key management in mobile and wireless adhoc networks
    Munirajan, Vignesh Kumar
    Cole, Eric
    [J]. PROCEEDINGS OF THE 10TH IASTED INTERNATIONAL CONFERENCE ON INTERNET AND MULTIMEDIA SYSTEMS AND APPLICATIONS, 2006, : 132 - +
  • [7] Efficient digital certificate verification in wireless public key infrastructure using enhanced certificate revocation list
    Prakasha, Krishna
    Muniyal, Balachandra
    Acharya, Vasundhara
    Krishna, Suyash
    Prakash, Smriti
    [J]. INFORMATION SECURITY JOURNAL, 2018, 27 (04): : 214 - 229
  • [8] A new public key certificate revocation scheme based on one-way hash chain
    Li, JF
    Zhu, YF
    Pan, H
    Wei, DW
    [J]. ADVANCES IN WEB-AGE INFORMATION MANAGEMENT, PROCEEDINGS, 2005, 3739 : 670 - 675
  • [9] CryptoRevocate: A Cryptographic Accumulator based Distributed Certificate Revocation List
    Ozcelik, Ilker
    Skjellum, Anthony
    [J]. 2021 IEEE 11TH ANNUAL COMPUTING AND COMMUNICATION WORKSHOP AND CONFERENCE (CCWC), 2021, : 865 - 872
  • [10] NPKI: Nested certificate based public key infrastructure
    Levi, A
    Caglayan, MU
    [J]. ADVANCES IN COMPUTER AND INFORMATION SCIENCES '98, 1998, 53 : 397 - 404