首页> 外文期刊>Computers & Security >A blockchain-based certificate revocation management and status verification system
【24h】

A blockchain-based certificate revocation management and status verification system

机译:基于区块的证书撤销管理和状态验证系统

获取原文
获取原文并翻译 | 示例

摘要

Revocation management is one of the main tasks of the Public Key Infrastructure (PKI). It is also critical to the security of any PKI. As a result of the increase in the number and sizes of networks as well as the adoption of novel paradigms such as the Internet of Things and their usage of the web, current revocation mechanisms are vulnerable to single point of failures as the network loads increase. To address this challenge, we take advantage of blockchains power and resiliency in order to propose an efficient decentralized certificates revocation management and status verification system. We use the extension field of the X509 certificate's structure to introduce a field that describes to which distribution point the certificate will belong to if revoked. Each distribution point is represented by a Bloom filter filled with revoked certificates. Bloom filters and revocation information are stored in a public blockchain. We developed a real implementation of our proposed mechanism in Python and the Namecoin blockchain. Then, we conducted an extensive evaluation of our scheme using performance metrics such as execution time and data consumption to demonstrate that it can meet the needed requirements with high efficiency and low cost. Moreover, we compare the performance of our approach with two of the most well-known/used revocation techniques which are Online Certificate Status Protocol (OCSP) and Certificate Revocation List (CRL). The results obtained show that our proposed approach outperforms these current schemes.
机译:撤销管理是公钥基础架构(PKI)的主要任务之一。对任何PKI的安全性也至关重要。由于网络的数量和大小的增加以及采用事物互联网等新颖范式及其网络,当前撤销机制易于单点故障,因为网络负载增加。为了解决这一挑战,我们利用区块的电力和弹性,以提出有效的分散证书撤销管理和状态验证系统。我们使用x509证书结构的扩展字段来介绍一个字段,该字段描述了证书将属于哪个分发点如果撤销。每个分发点由填充有撤销证书的盛开过滤器表示。绽放过滤器和撤销信息存储在公共区块链中。我们在Python和NameCoin区块链中制定了我们所提出的机制。然后,我们使用执行时间和数据消耗等性能指标对我们的方案进行了广泛的评估,以证明它可以以高效率和低成本满足所需的要求。此外,我们将我们的方法的性能与两个最着名/使用的吊销技术进行比较,这些撤销技术是在线证书状态协议(OCSP)和证书撤销列表(CRL)。得到的结果表明,我们所提出的方法优于这些目前的方案。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号