Windowed Key Revocation in Public Key Infrastructures

نویسندگان

  • Patrick McDaniel
  • Sugih Jamin
چکیده

A fundamental problem inhibiting the wide acceptance of a Public Key Infrastructure (PKI) in the Internet is the lack of a mechanism that provides scalable certificate revocation. In this paper, we propose a novel mechanism called Windowed Revocation. In windowed revocation, certificate revocation is announced for short periods in periodic Certificate Revocation Lists (CRLs). Due to the assurances provided by the protocol over which certificates are retrieved, we bound the amount of time that any certificate is cached by users. Thus, we can limit the announcement of revocation only to the time in which the certificate may be cached; not until its expiration. Because the time in which certificate are announced is short, CRLs are similarly small. By limiting the size of CRLs, we are able to integrate other mechanisms that increase the scalability of the PKI. One such mechanism is the use of “pushed” CRLs using multicast. We include a proof of the correctness of our approach.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Windowed Certificate Revocation

The advent of electronic commerce and personal communications on the Internet heightens concerns over the lack of privacy and security. Network services providing a wide range of security related guarantees are increasingly based on public key certificates. A fundamental problem inhibiting the wide acceptance of existing certificate distribution services is the lack of a scalable certificate re...

متن کامل

PKI and Revocation Survey

This survey covers basic information about public key infrastructures and summarizes the predominant technology and standards. Special attention is given to mechanisms for certificate revocation. Methods for CRL distribution and validity checking are compared. Supported by KDD R&D Laboratories, Inc.

متن کامل

Empirical Analysis of Certificate Revocation Lists

Managing public key certificates revocation has long been a central issue in public key infrastructures. Though various certificate revocation mechanisms have been proposed to address this issue, little effort has been devoted to the empirical analysis of real-world certificate revocation data. In this paper, we conduct such an empirical analysis based on a large amount of data collected from V...

متن کامل

Eecient Certiicate Revocation

We apply o -line/on-line signatures to provide an alternative solution to the problem of certi cate revocation. The new systems dismiss with traditional CRLs (Certi cate Revocation Lists) and yield public-key infrastructures that are substantially cheaper to run than traditional ones.

متن کامل

User - friendly process algebra compiler

While the technologies for generation of electronic signatures are well-established in public-key infrastructures, the validation of electronic signatures still shows some open problems. The verification of the validity of an electronic signature requires high degrees of diligence, time and effort for the local configuration and management of trusted certificates and their revocation status. A ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 1998