...
首页> 外文期刊>Selected Areas in Communications, IEEE Journal on >Efficient Certificate Revocation List Organization and Distribution
【24h】

Efficient Certificate Revocation List Organization and Distribution

机译:高效的证书吊销列表的组织和分发

获取原文
获取原文并翻译 | 示例
           

摘要

In this paper, we propose a lightweight mechanism for revoking security certificates that is appropriate for the limited bandwidth and hardware cost constraints of a VANET. A Certificate Authority (CA) issues certificates to trusted nodes, i.e., vehicles. If the CA looses trust in a vehicle (e.g., due to evidence of malfunction or malicious behavior), the CA must promptly revoke the certificates of the distrusted vehicle. To distribute revocation information quickly even during incremental deployment, we propose that CAs use Certificate Revocation Lists (CRLs). The CRL should be composed in a secure manner, and it should be exchanged in a way such that the CRL is both quickly and widely distributed. We previously proposed a mechanism for the quick distribution of CRL updates that also covers a wide area by using vehicle-to-vehicle (V2V) communication . In this paper, we additionally investigate the performance of V2V communication in partial deployment scenarios, that is, where only a certain percentage of vehicles are equipped with VANET radios. We provide simulation results that show our V2V exchange mechanism is quicker than distributing CRLs or CRL updates through road-side units (RSUs) alone. However, this revocation process, which involves both the CA and vehicles, must conform to the aforementioned bandwidth and hardware restrictions. In this paper, we present mechanisms that achieve the goals of reduced CRL size, a computationally efficient mechanism for determining if a certificate is on the CRL, and a lightweight mechanism for exchanging CRL updates. Additionally, we expand on our previous work to provide privacy to revoked vehicles prior to their revocation.
机译:在本文中,我们提出了一种用于撤销安全证书的轻量级机制,该机制适用于VANET的有限带宽和硬件成本约束。证书颁发机构(CA)将证书颁发给受信任的节点,即车辆。如果CA放弃对车辆的信任(例如,由于故障或恶意行为的证据),则CA必须立即撤销不信任车辆的证书。为了即使在增量部署期间也可以快速分发吊销信息,我们建议CA使用证书吊销列表(CRL)。 CRL应该以安全的方式组成,并且应该以快速,广泛分布CRL的方式进行交换。我们之前提出了一种用于快速分发CRL更新的机制,该机制还可以通过使用车对车(V2V)通信来覆盖广泛的区域。在本文中,我们还研究了部分部署情况下V2V通信的性能,即只有一定百分比的车辆配备了VANET无线电。我们提供的仿真结果表明,V2V交换机制比仅通过路边单元(RSU)分发CRL或CRL更新要快。但是,涉及CA和车辆的此吊销过程必须符合上述带宽和硬件限制。在本文中,我们介绍了实现减少CRL大小的目标的机制,一种用于确定证书是否在CRL上的计算有效机制以及用于交换CRL更新的轻量级机制。此外,我们扩展了以前的工作,以在撤消之前为已撤消的车辆提供隐私。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号