Efficient Certificate Revocation : A P2P Approach
نویسندگان
چکیده
Certificate revocation is one of the many challenges faced by Public Key Infrastructure (PKI). Certificate revocation is the action of declaring a certificate, which has not expired, is no longer valid due to various reasons ranging from change of relationship between certificate issuer and the public key owner to compromised private keys of the associated certificate to change of information contained in the certificate. All the revoked certificates by the certificate issuer must be made available to all the end-entities, which need to verify a certificate. Many schemes have been proposed for certificate revocation; each with its own strenghts and weaknesses. Some of these schemes, although straightforward and easy to implement, suffer when faced with the challenge of efficient distribution of certificate revocation information. In this paper we look into the use of Peer-to-Peer (P2P) technology to effectively and efficiently distribute the revoked information. P2P is an emerging paradigm that is now viewed as a potential technology that could re-formulate well known distributed architectures (e.g., the Internet). It is a network architecture in which all participating computers (or nodes), in most cases, have equivalent capabilities and responsibilities. Certificate revocation schemes such as Certification Revocation Lists, which has the potential to distribute very large list, will definitely benefit from the P2P implementation.
منابع مشابه
Using CRL Push Delivery for Efficient Certificate Revocation Information Distribution in Grids
Checking revocation information is necessary to prevent from using digital certificates whose contents become invalid. In current system either periodical retrieval of Certificate Revocation Lists (CRLs) or the Online Certificate Status Protocol (OCSP) are the most common mechanisms to access revocation information issued by the certification authorities. As both these approaches pose problems ...
متن کاملEnergy Efficient and Improved Certificate Revocation Technique for Mobile Ad Hoc Networks
Mobile ad-hoc networks are self-organizing as well as self configurable with an open network environment. The nodes during this network will be a part of can freely leave from the network. Therefore, the wireless and dynamic natures of MANET create them a lot of vulnerable in the direction of numerous varieties of security attacks than their wired counterparts. To ensure the secure network serv...
متن کاملReduced Overhead Based Approach for Secure Communication in Mobile Ad Hoc Network
Mobile ad hoc network (MANET) is an infrastructureless mobile networks where nodes can freely move and join. MANET has attracted much attention in recent years owing to the increased focus on wireless communication. It is a highly flexible network, vulnerable to various types of security attacks by malicious nodes. Ensuring network security is a major concern in the case of MANET. Certificate r...
متن کاملTOC Approach to Recertification in Public Key Infrastructure
TOC provides a systematic methodology to verbalize intuition and formulate effective solutions for difficult problems. Efficient and timely distribution of certificate revocation information is one of the biggest challenges faced by PKI implementers. In this paper, we demonstrate the use of TOC Thinking Process tools to develop an intuitive and effective solution for the hard problem of managin...
متن کاملEPA: An efficient and privacy-aware revocation mechanism for vehicular ad hoc networks
Security is vital for the reliable operation of vehicular ad hoc networks (VANETs). One of the critical security issues is the revocation of misbehaving vehicles. While essential, revocation checking can leak private information. In particular, repositories receiving the certificate status queries could infer the identity of the vehicles posing the query and the target of the query. An importan...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2002