A Certificate Revocation Scheme for a Large-Scale Highly Replicated Distributed System

  • Authors:
  • Bogdan C. Popescu;Bruno Crispo;Andrew S. Tanenbaum

  • Affiliations:
  • -;-;-

  • Venue:
  • ISCC '03 Proceedings of the Eighth IEEE International Symposium on Computers and Communications
  • Year:
  • 2003

Quantified Score

Hi-index 0.00

Visualization

Abstract

A common way to protect objects in distributed systemsis to issue authorization certificates to users, which theypresent to gain access. In some situations a way is needed torevoke existing certificates. Current methods, such as havinga master revocation list, have been designed to workefficiently with identity certificates, and do not take into accountthe delegation of certificate-issuing rights requiredwhen implementing complex administrative hierarchies forlarge distributed applications. In this paper we presenta novel mechanism for revoking authorization certificatesbased on clustering users and servers, and present argumentsshowing that it is more efficient than other methods.We also discuss a way for probabilistically auditingthe use of the revocation mechanism proposed to reduce thechances of any component behaving maliciously.