Windowed certificate revocation
- 7 November 2002
- conference paper
- Published by Institute of Electrical and Electronics Engineers (IEEE)
- Vol. 3 (0743166X) , 1406-1414 vol.3
- https://doi.org/10.1109/infcom.2000.832538
Abstract
The advent of electronic commerce and personal communications on the Internet has heightened concern over lack of privacy and security. Network services providing a wide range of security related guarantees are increasingly based on public key certificates. A fundamental problem inhibiting the wide acceptance of existing certificate distribution services is the lack of a scalable certificate revocation mechanism. We argue in this paper that the resource requirements of extant revocation mechanisms place a significant burden on certificate servers and network resources. We propose a novel mechanism called windowed revocation that satisfies the security policies and requirements of existing mechanisms and, at the same time, reduces the burden on certificate servers and network resources. We include a proof of correctness of windowed revocation and analyze worst case performance scenarios.Keywords
This publication has 12 references indexed in Scilit:
- Certificate revocation and certificate updateIEEE Journal on Selected Areas in Communications, 2000
- X.509 Internet Public Key Infrastructure Online Certificate Status Protocol - OCSPPublished by RFC Editor ,1999
- Domain Name System Security ExtensionsPublished by RFC Editor ,1999
- On certificate revocation and validationPublished by Springer Nature ,1998
- Can we eliminate certificate revocation lists?Published by Springer Nature ,1998
- Certificate revocation: Mechanics and meaningPublished by Springer Nature ,1998
- Internet Privacy Enhanced MailCommunications of the ACM, 1993
- Privacy Enhancement for Internet Electronic Mail: Part II: Certificate-Based Key ManagementPublished by RFC Editor ,1993
- An analysis of wide-area name server trafficPublished by Association for Computing Machinery (ACM) ,1992
- Multicast routing in datagram internetworks and extended LANsACM Transactions on Computer Systems, 1990