首页> 外文会议>International conference on financial cryptography >A Response to 'Can We Eliminate Certificate Revocation Lists?'
【24h】

A Response to 'Can We Eliminate Certificate Revocation Lists?'

机译:对“我们可以消除证书撤销列表的回应?”

获取原文

摘要

The massive growth of electronic commerce on the Internet heightens concerns over the lack of meaningful certificate management. One issue limiting the availability of such services is the absence of scalable certificate revocation. The use of certificate revocation lists (CRLs) to convey revocation state in public key infrastructures has long been the subject of debate. Centrally, opponents of the technology attribute a range of semantic and technical limitations to CRLs. In this paper, we consider arguments advising against the use of CRLs made principally by Rivest in his paper "Can we eliminate certificate revocation lists?". Specifically, the assumptions and environments on which these arguments are based are separated from those features inherent to CRLs. We analyze the requirements and potential solutions for three distinct PKI environments. The fundamental tradeoffs between revocation technologies are identified. From the case study analysis we show how, in some environments, CRLs are the most efficient vehicle for distributing revocation state. The lessons learned from our case studies are applied to a realistic PKI environment. The result, revocation on demand, is a CRL based mechanism providing timely revocation information.
机译:互联网上的电子商务的大规模增长提高了缺乏有意义的证书管理。限制此类服务可用性的一个问题是缺乏可扩展的证书撤销。使用证书撤销列表(CRL)将在公钥基础架构中传达撤销状态长期以来一直是辩论的主题。集中的,技术的对手将一系列语义和技术限制归因于CRL。在本文中,我们考虑在他的论文中通过最活跃的r型克利斯的争论“我们可以消除证书撤销列表吗?”。具体地,这些参数的假设和环境基于基于CRL所固有的这些特征。我们分析了三个不同的PKI环境的要求和潜在解决方案。确定了撤销技术之间的基本权衡。从案例研究分析,我们展示了在某些环境中如何,CRL是用于分配撤销状态的最有效的车辆。我们案例研究中吸取的经验教训适用于逼真的PKI环境。结果,撤销按需,是基于CRL的机制,提供了及时撤销信息。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号