Towards a framework for evaluating certificate status information mechanisms

被引:18
作者
Iliadis, J
Gritzalis, S
Spinellis, D
De Cock, D
Preneel, B
Gritzalis, D
机构
[1] Univ Aegean, Dept Informat & Commun Syst Engn, Res Unit, GR-11472 Athens, Greece
[2] Athens Univ Econ & Business, Dept Management Sci & Technol, GR-10434 Athens, Greece
[3] Katholieke Univ Leuven, Dept Elect Engn, ESAT, COSIC, B-3001 Heverlee, Belgium
[4] Athens Univ Econ & Business, Dept Informat, GR-10434 Athens, Greece
关键词
certificate; certificate revocation; certificate status; Certificate Revocation List; certificate revocation status; certificate revocation tree; evaluation framework;
D O I
10.1016/S0140-3664(03)00079-3
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
A wide spectrum of certificate revocation mechanisms is currently in use. A number of them have been proposed by standardisation bodies, while some others have originated from academic or private institutions. What is still missing is a systematic and robust framework for the sound evaluation of these mechanisms. We present a mechanism-neutral framework for the evaluation of certificate status information (CSI) mechanisms. These mechanisms collect, process and distribute CSI. A detailed demonstration of its exploitation is also provided. The demonstration is mainly based on the evaluation of Certificate Revocation Lists, as well as of the Online Certificate Status Protocol. Other well-known CSI mechanisms are also mentioned for completeness. (C) 2003 Elsevier B.V. All rights reserved.
引用
收藏
页码:1839 / 1850
页数:12
相关论文
共 22 条
[1]  
Adams C, 1999, INTERNET X 509 PUBLI
[2]  
Adams Carlisle, GEN FLEXIBLE APPROAC
[3]  
[Anonymous], INTERNET X 509 PUBLI
[4]  
Berkovits S., 1994, PUBLIC KEY INFRASTRU
[5]  
Berners-Lee Tim, 1998, UNIFORM RESOURCE IDE
[6]  
CHADWICK DW, 1999, INTERNET X 509 PUBLI
[7]  
FOX B, 1998, LNCS, V1465
[8]  
HALLAMBAKER P, 1999, OCSP EXTENSIONS IETF
[9]  
HOUSLEY R, 1999, IETF PKIX WORKING GR
[10]  
Housley R., 1999, INTERNET X 509 PUBLI