Report
Postcertificates for Revocation Transparency
العنوان: | Postcertificates for Revocation Transparency |
---|---|
المؤلفون: | Korzhitskii, Nikita, Nemec, Matus, Carlsson, Niklas |
سنة النشر: | 2022 |
المجموعة: | Computer Science |
مصطلحات موضوعية: | Computer Science - Cryptography and Security, Computer Science - Computers and Society, Computer Science - Networking and Internet Architecture, C.2, E.3, C.4 |
الوصف: | The modern Internet is highly dependent on trust communicated via certificates. However, in some cases, certificates become untrusted, and it is necessary to revoke them. In practice, the problem of secure revocation is still open. Furthermore, the existing procedures do not leave a transparent and immutable revocation history. We propose and evaluate a new revocation transparency protocol that introduces postcertificates and utilizes the existing Certificate Transparency (CT) logs. The protocol is practical, has a low deployment cost, provides an immutable history of revocations, enables delegation, and helps to detect revocation-related misbehavior by certificate authorities (CAs). With this protocol, a holder of a postcertificate can bypass the issuing CA and autonomously initiate the revocation process via submission of the postcertificate to a CT log. The CAs are required to monitor CT logs and proceed with the revocation upon detection of a postcertificate. Revocation status delivery is performed independently and with an arbitrary status protocol. Postcertificates can increase the accountability of the CAs and empower the certificate owners by giving them additional control over the status of the certificates. We evaluate the protocol, measure log and monitor performance, and conclude that it is possible to provide revocation transparency using existing CT logs. |
نوع الوثيقة: | Working Paper |
URL الوصول: | http://arxiv.org/abs/2203.02280 |
رقم الانضمام: | edsarx.2203.02280 |
قاعدة البيانات: | arXiv |
ResultId |
1 |
---|---|
Header |
edsarx arXiv edsarx.2203.02280 1032 3 Report report 1032.35046386719 |
PLink |
https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&scope=site&db=edsarx&AN=edsarx.2203.02280&custid=s6537998&authtype=sso |
FullText |
Array
(
[Availability] => 0
)
Array ( [0] => Array ( [Url] => http://arxiv.org/abs/2203.02280 [Name] => EDS - Arxiv [Category] => fullText [Text] => View record in Arxiv [MouseOverText] => View record in Arxiv ) ) |
Items |
Array
(
[Name] => Title
[Label] => Title
[Group] => Ti
[Data] => Postcertificates for Revocation Transparency
)
Array ( [Name] => Author [Label] => Authors [Group] => Au [Data] => <searchLink fieldCode="AR" term="%22Korzhitskii%2C+Nikita%22">Korzhitskii, Nikita</searchLink><br /><searchLink fieldCode="AR" term="%22Nemec%2C+Matus%22">Nemec, Matus</searchLink><br /><searchLink fieldCode="AR" term="%22Carlsson%2C+Niklas%22">Carlsson, Niklas</searchLink> ) Array ( [Name] => DatePubCY [Label] => Publication Year [Group] => Date [Data] => 2022 ) Array ( [Name] => Subset [Label] => Collection [Group] => HoldingsInfo [Data] => Computer Science ) Array ( [Name] => Subject [Label] => Subject Terms [Group] => Su [Data] => <searchLink fieldCode="DE" term="%22Computer+Science+-+Cryptography+and+Security%22">Computer Science - Cryptography and Security</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+Science+-+Computers+and+Society%22">Computer Science - Computers and Society</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+Science+-+Networking+and+Internet+Architecture%22">Computer Science - Networking and Internet Architecture</searchLink><br /><searchLink fieldCode="DE" term="%22C%2E2%22">C.2</searchLink><br /><searchLink fieldCode="DE" term="%22E%2E3%22">E.3</searchLink><br /><searchLink fieldCode="DE" term="%22C%2E4%22">C.4</searchLink> ) Array ( [Name] => Abstract [Label] => Description [Group] => Ab [Data] => The modern Internet is highly dependent on trust communicated via certificates. However, in some cases, certificates become untrusted, and it is necessary to revoke them. In practice, the problem of secure revocation is still open. Furthermore, the existing procedures do not leave a transparent and immutable revocation history. We propose and evaluate a new revocation transparency protocol that introduces postcertificates and utilizes the existing Certificate Transparency (CT) logs. The protocol is practical, has a low deployment cost, provides an immutable history of revocations, enables delegation, and helps to detect revocation-related misbehavior by certificate authorities (CAs). With this protocol, a holder of a postcertificate can bypass the issuing CA and autonomously initiate the revocation process via submission of the postcertificate to a CT log. The CAs are required to monitor CT logs and proceed with the revocation upon detection of a postcertificate. Revocation status delivery is performed independently and with an arbitrary status protocol. Postcertificates can increase the accountability of the CAs and empower the certificate owners by giving them additional control over the status of the certificates. We evaluate the protocol, measure log and monitor performance, and conclude that it is possible to provide revocation transparency using existing CT logs. ) Array ( [Name] => TypeDocument [Label] => Document Type [Group] => TypDoc [Data] => Working Paper ) Array ( [Name] => URL [Label] => Access URL [Group] => URL [Data] => <link linkTarget="URL" linkTerm="http://arxiv.org/abs/2203.02280" linkWindow="_blank">http://arxiv.org/abs/2203.02280</link> ) Array ( [Name] => AN [Label] => Accession Number [Group] => ID [Data] => edsarx.2203.02280 ) |
RecordInfo |
Array
(
[BibEntity] => Array
(
[Subjects] => Array
(
[0] => Array
(
[SubjectFull] => Computer Science - Cryptography and Security
[Type] => general
)
[1] => Array
(
[SubjectFull] => Computer Science - Computers and Society
[Type] => general
)
[2] => Array
(
[SubjectFull] => Computer Science - Networking and Internet Architecture
[Type] => general
)
[3] => Array
(
[SubjectFull] => C.2
[Type] => general
)
[4] => Array
(
[SubjectFull] => E.3
[Type] => general
)
[5] => Array
(
[SubjectFull] => C.4
[Type] => general
)
)
[Titles] => Array
(
[0] => Array
(
[TitleFull] => Postcertificates for Revocation Transparency
[Type] => main
)
)
)
[BibRelationships] => Array
(
[HasContributorRelationships] => Array
(
[0] => Array
(
[PersonEntity] => Array
(
[Name] => Array
(
[NameFull] => Korzhitskii, Nikita
)
)
)
[1] => Array
(
[PersonEntity] => Array
(
[Name] => Array
(
[NameFull] => Nemec, Matus
)
)
)
[2] => Array
(
[PersonEntity] => Array
(
[Name] => Array
(
[NameFull] => Carlsson, Niklas
)
)
)
)
[IsPartOfRelationships] => Array
(
[0] => Array
(
[BibEntity] => Array
(
[Dates] => Array
(
[0] => Array
(
[D] => 03
[M] => 03
[Type] => published
[Y] => 2022
)
)
)
)
)
)
)
|
IllustrationInfo |