Certificate revocation and certificate update

被引:121
作者
Naor, M [1 ]
Nissim, K [1 ]
机构
[1] Weizmann Inst Sci, Dept Appl Math & Comp Sci, IL-76100 Rehovot, Israel
关键词
authenticated data structures; certificates; PKI;
D O I
10.1109/49.839932
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
We present a solution for the problem of certificate revocation, This solution represents certificate revocation lists by authenticated dictionaries that support: 1) efficient verification whether a certificate is In the list or not and 2) efficient updates (adding/removing certificates from the list). The suggested solution gains in scalability, communication costs, robustness to parameter changes, and update rate. Comparisons to the following solutions land variants) are Included: "traditional" certificate revocation lists (CRL's), Micali's certificate revocation system (CRS), and Kocher's certificate revocation trees (CRT). We also consider a scenario in which certificates are not revoked, but frequently issued for short-term periods. Based on the authenticated dictionary scheme, a certificate update scheme is presented in which all certificates are updated by a common message. The suggested solutions for certificate revocation and certificate update problems are better than current solutions with respect to communication costs, update rate, and robustness to changes In parameters, and are compatible, e.g., with X.500 certificates.
引用
收藏
页码:561 / 570
页数:10
相关论文
共 24 条
  • [1] Aho A. V., 1983, DATA STRUCTURES ALGO
  • [2] Aiello W, 1998, LECT NOTES COMPUT SC, V1462, P137, DOI 10.1007/BFb0055725
  • [3] [Anonymous], 1994, LNCS
  • [4] [Anonymous], MITLCSTM542B
  • [5] [Anonymous], 1995, NETWORK SECURITY PRI
  • [6] Bellare M., 1995, Proceedings of the Twenty-Seventh Annual ACM Symposium on the Theory of Computing, P45, DOI 10.1145/225058.225080
  • [7] Bellare M, 1997, LECT NOTES COMPUT SC, V1294, P470
  • [8] CHECKING THE CORRECTNESS OF MEMORIES
    BLUM, M
    EVANS, W
    GEMMELL, P
    KANNAN, S
    NAOR, M
    [J]. ALGORITHMICA, 1994, 12 (2-3) : 225 - 244
  • [9] Brands Stefan, 1993, CSR9323 CWI
  • [10] CHAUM D, 1992, LECT NOTES COMPUT SC, V576, P470