首页> 外文期刊>International Journal of Information Security >Privacy-preserving revocation checking
【24h】

Privacy-preserving revocation checking

机译:保留隐私的撤销检查

获取原文
获取原文并翻译 | 示例
获取外文期刊封面目录资料

摘要

Digital certificates signed by trusted certification authorities (CAs) are used for multiple purposes, most commonly for secure binding of public keys to names and other attributes of their owners. Although a certificate usually includes an expiration time, it is not uncommon that a certificate needs to be revoked prematurely. For this reason, whenever a client (user or program) needs to assert the validity of another party’s certificate, it performs a certificate revocation check. There are several revocation techniques varying in both the operational model and underlying data structures. One common feature is that a client typically contacts some third party (whether trusted, untrusted or semi-trusted) and obtains some evidence of either revocation or validity (non-revocation) for the certificate in question. While useful, revocation checking can leak sensitive information. In particular, third parties of dubious trustworthiness can discover the identity of the party performing the revocation check, as well as the target of the check. The former can be easily remedied with techniques such as onion routing or anonymous web browsing. Whereas, hiding the target of the query is not obvious. This paper focuses on the privacy in revocation checking, explores the loss of privacy in current revocation checking techniques and proposes simple and efficient privacy-preserving techniques for two well-known revocation methods.
机译:由受信任的证书颁发机构(CA)签名的数字证书有多种用途,最常见的是将公钥安全绑定到其所有者的名称和其他属性。尽管证书通常包含到期时间,但证书需要过早吊销并不罕见。因此,只要客户端(用户或程序)需要声明另一方证书的有效性,便会执行证书吊销检查。在操作模型和基础数据结构中都有几种撤销技术。一个共同的特征是,客户通常会联系某个第三方(无论是受信任的,不受信任的还是半受信任的),并获得有关证书的吊销或有效性(非吊销)的一些证据。吊销检查虽然有用,但可以泄漏敏感信息。特别地,可疑可信度的第三方可以发现执行吊销检查的一方的身份,以及检查的目标。前者可以通过洋葱路由或匿名Web浏览等技术轻松修复。而隐藏查询目标并不明显。本文着重于吊销检查中的隐私,探讨了当前吊销检查技术中的隐私损失,并针对两种众所周知的吊销方法提出了简单有效的隐私保护技术。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号