A novel approach to certificate revocation management

  • Authors:
  • Ravi Mukkamala;Sushil Jajodia

  • Affiliations:
  • -;-

  • Venue:
  • Das'01 Proceedings of the fifteenth annual working conference on Database and application security
  • Year:
  • 2001

Quantified Score

Hi-index 0.00

Visualization

Abstract

With the ever-increasing growth in electronic messaging and electronic commerce, the need for an infrastructure to provide confidentiality, security, and confidence for such exchanges to take place is quite evident [2]. Here, public keys and certificates are issued to users for authorization purposes. One of the primary concerns in these systems is the handling of certificate revocation prior to the expiration date. In this paper, we propose a new approach for managing certificate revocation. All existing schemes require that the information about revoked certificates be sent only periodically to the directories used for verification. This gives rise to the problem of obsolescence. To overcome this problem, we have introduced a new layer in the traditional architecture. Using a preliminary analysis, we show the impact of the new scheme on the up-to-datedness, robustness, load distribution, and response time of the system. Similarly, we show the additional costs incurred in terms of communication cost, processing cost, and hardware costs.