Revocation scheme for PMI based upon the tracing of certificates chains

  • Authors:
  • M. Francisca Hinarejos;Jordi Forné

  • Affiliations:
  • Department of Telematics Engineering (ENTEL), Technical University of Catalonia (UPC), Barcelona, Spain;Department of Telematics Engineering (ENTEL), Technical University of Catalonia (UPC), Barcelona, Spain

  • Venue:
  • ICCSA'06 Proceedings of the 2006 international conference on Computational Science and Its Applications - Volume Part IV
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

Public Key Infrastructure (PKI) and Privilege Management Infrastructure (PMI) can respectively be used to support authentication and authorization in distributed scenarios. The validation of certificate chains is a critical issue in both infrastructures, because it requires several costly processes, such as certificate path discovery, validation of each certificate, and so on. The problem becomes even worst in devices with limited resources (battery, memory, computational capacity, etc.) as mobile devices. In this paper we present an architecture that reduces the communication and computational overhead of certificate status checking in a complete certificate chain. The proposed tracing of the certificates chains is based on a cascade certificate revocation policy.