首页> 外文期刊>Quality and Reliability Engineering International >Evaluating Intrusion-Tolerant Certification Authority Systems
【24h】

Evaluating Intrusion-Tolerant Certification Authority Systems

机译:评估容错证书颁发机构系统

获取原文
获取原文并翻译 | 示例
       

摘要

Various intrusion-tolerant certification authority (CA) systems have been proposed to provide attack resilient certificate signing (or update) services. However, it is difficult to compare them against each other directly, due to the diversity in system organizations, threshold signature schemes, protocols and usage scenarios. We present a framework for intrusion-tolerant CA system evaluation, which consists of three components, namely, an intrusion-tolerant CA model, a threat model and a metric for comparative evaluation. The evaluation framework covers system organizations, protocols, usage scenarios, the period of certificate validity, the revocation rate and the mean time to recovery. Based on the framework, four representative systems are evaluated and compared in three typical usage scenarios, producing reasonable and insightful results. The interdependence between usage scenarios and system characteristics is investigated, providing a guideline to design better systems for different usage scenarios. The proposed framework provides an effective and practicable method to evaluate intrusion-tolerant CA systems quantitatively, and helps customers to choose and configure an intrusion-tolerant CA system. Moreover, the comparison results offer valuable insights to further improve the attack resilience of intrusion-tolerant CA systems.
机译:已经提出了各种入侵容忍证书颁发机构(CA)系统来提供具有抗攻击性的证书签名(或更新)服务。但是,由于系统组织,阈值签名方案,协议和使用方案的多样性,很难直接将它们彼此进行比较。我们提出了一种容错CA系统评估的框架,该框架包括三个部分,即容错CA模型,威胁模型和比较评估指标。评估框架涵盖系统组织,协议,使用方案,证书有效期,吊销率和平均恢复时间。基于该框架,在三个典型的使用场景中对四个代表性系统进行了评估和比较,从而产生了合理而有见地的结果。研究了使用场景和系统特性之间的相互依赖关系,为为不同的使用场景设计更好的系统提供了指导。所提出的框架提供了一种有效且可行的方法,用于定量评估容错CA系统,并帮助客户选择和配置容错CA系统。而且,比较结果提供了宝贵的见解,可以进一步提高容忍CA系统的攻击弹性。

著录项

  • 来源
    《Quality and Reliability Engineering International》 |2012年第8期|p.825-841|共17页
  • 作者单位

    State Key Laboratory of Information Security, Graduate University of Chinese Academy of Sciences, Beijing 100049, China,College of Information Sciences and Technology, Pennsylvania State University, University Park, PA 16802, USA;

    State Key Laboratory of Information Security, Graduate University of Chinese Academy of Sciences, Beijing 100049, China;

    College of Information Sciences and Technology, Pennsylvania State University, University Park, PA 16802, USA;

  • 收录信息 美国《科学引文索引》(SCI);美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    attack resilience; certification authority; evaluation; intrusion tolerance; public key infrastructure;

    机译:攻击弹性认证机构;评估;入侵容忍公钥基础设施;
  • 入库时间 2022-08-17 13:09:46

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号