...
首页> 外文期刊>The Computer journal >Certificate Revocation List Distribution System for the KAD Network
【24h】

Certificate Revocation List Distribution System for the KAD Network

机译:KAD网络的证书吊销列表分发系统

获取原文
获取原文并翻译 | 示例
           

摘要

Many peer-to-peer (p2p) overlays require certain security services which could be provided through a Public Key Infrastructure. However, these infrastructures are bound up with a revocation system, such as Certificate Revocation Lists (CRLs). A system with a client/server structure, where a Certificate Authority plays a role of a central server, is prone to suffer from common problems of a single point of failure. If only one Authority has to distribute the whole CRL to all users, perhaps several millions in a structured p2p overlay, a bottleneck problem appears. Moreover, in these networks, users often have a set of pseudonyms that are bound to a certificate, which gives rise to two additional issues: issuing the CRL and assuring its freshness. On the one hand, the list size grows exponentially with the number of network users. On the other hand, these lists must be updated more frequently; otherwise the revocation data will not be fresh enough. To solve these problems, we propose a new distributed revocation system for the Kademlia network. Our system distributes CRLs using the overlay itself and, to not compromise the storage of nodes, lists are divided into segments. This mechanism improves the accessibility, increases the availability and guarantees the freshness of the revocation data.
机译:许多对等(p2p)覆盖都需要某些安全服务,这些服务可以通过公钥基础结构提供。但是,这些基础结构与吊销系统绑定在一起,例如证书吊销列表(CRL)。具有客户机/服务器结构的系统(证书颁发机构扮演中央服务器的角色)容易遭受单点故障的常见问题的困扰。如果只有一个授权机构将整个CRL分发给所有用户,可能是结构化的p2p覆盖中的数以百万计的用户,则会出现瓶颈问题。而且,在这些网络中,用户通常具有一组绑定到证书的假名,这引起了两个附加问题:颁发CRL和确保其新鲜度。一方面,列表大小随着网络用户数量呈指数增长。另一方面,这些列表必须更频繁地更新。否则,吊销数据将不够新鲜。为了解决这些问题,我们为Kademlia网络提出了一种新的分布式吊销系统。我们的系统使用覆盖图本身来分发CRL,并且为了不损害节点的存储,将列表分为多个部分。该机制提高了可访问性,提高了可用性并保证了撤销数据的新鲜度。

著录项

  • 来源
    《The Computer journal》 |2014年第2期|273-280|共8页
  • 作者单位

    Department of Telematics Engineering (ENTEL), Universitat Politecnica de Catalunya (UPC), Barcelona, Spain;

    Department of Telematics Engineering (ENTEL), Universitat Politecnica de Catalunya (UPC), Barcelona, Spain;

    Department of Telematics Engineering (ENTEL), Universitat Politecnica de Catalunya (UPC), Barcelona, Spain;

    Department of Telematics Engineering (ENTEL), Universitat Politecnica de Catalunya (UPC), Barcelona, Spain;

    Department of Telematics Engineering (ENTEL), Universitat Politecnica de Catalunya (UPC), Barcelona, Spain;

    Department of Telematics Engineering (ENTEL), Universitat Politecnica de Catalunya (UPC), Barcelona, Spain;

  • 收录信息 美国《科学引文索引》(SCI);美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Certificate Revocation List (CRL); structured peer-to-peer (P2P) overlay; KAD network;

    机译:证书吊销列表(CRL);结构化对等(P2P)覆盖;KAD网络;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号