首页> 外文会议>IASTED conference on communication, network, and information security >AN EFFICIENT AND SECURE ALTERNATIVE TO OCSP FOR PUBLIC-KEY CERTIFICATE REVOCATION
【24h】

AN EFFICIENT AND SECURE ALTERNATIVE TO OCSP FOR PUBLIC-KEY CERTIFICATE REVOCATION

机译:用于公共关键证书撤销的OCSP有效和安全的替代方案

获取原文

摘要

This paper presents an on-line method for efficient authentication and verification of certificate status within Public-Key Infrastructures (PKIs). The proposed method has been devised as an alternative to the well-known Online Certificate Status Protocol (OCSP): it exhibits the same positive features of as regards scalability, security, timeliness and expressive power while significantly reducing the directory computational load, a particularly remarkable benefit especially in high-traffic scenarios, where performance bottlenecks could be exploited to induce a denial-of-service over the directory. This key feature has been achieved by means of a purposely conceived extension of the One-Way Accumulator (OWA) cryptographic primitive, which permits to provide an explicit, concise, authenticated and not forgeable proof about the revocation status of each certificate. A thorough investigation on the performance attainable shows that the devised method allows reducing the computational load up to an order of magnitude under normal operating conditions of the PKI in which it is deployed, and, for very intensive query activity, even to fix an upper bound independent from the rate PKI users perform certificate status verification operations.
机译:本文提出了一种用于高效认证和验证公钥基础架构(PKI)的证书状态的在线方法。已经设计了所提出的方法作为众所周知的在线证书状态协议(OCSP)的替代方案:它表现出相同的正面特征,即在可扩展性,安全性,及时性和表现力和表现力,同时显着减少目录计算负荷,特别是显着的尤其是在高流量方案中的好处,可以利用性能瓶颈来诱导目录拒绝服务。该关键特征是通过无意构思的单向累加器(OWA)加密原语的扩展来实现的,这允许提供关于每个证书的撤销状态的显式,简洁,认证和不可伪造的证明。对可达到的性能的彻底调查表明,设计的方法允许将计算负载降低到部署的PKI的正常操作条件下的数量级,并且对于非常密集的查询活动,甚至可以修复上限独立于PKI用户的速率执行证书状态验证操作。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号