RITM: Revocation in the Middle

RITM: Revocation in the Middle
复制标题

RITM:中间撤销

DOI:
10.1109/icdcs.2016.91
复制
发表时间:
2016
期刊:
2016 IEEE 36th International Conference on Distributed Computing Systems (ICDCS)
影响因子:
--
通讯作者:
A. Perrig
A. Perrig
中科院分区:
--
文献类型:
--
作者:
Pawel Szalachowski;L. Chuat;Taeho Lee;A. Perrig

文献摘要

被引文献

相似文献

尽管许多关键应用程序每天都使用 TLS,但它所依赖的公钥基础设施仍然缺乏足够的撤销机制。理想的撤销机制应该是廉价、高效、安全且保护隐私的。此外,普遍加密的上升趋势带来了现代撤销系统应该解决的新的可扩展性挑战。在本文中,我们研究网络节点如何向客户端传递证书有效性信息。我们提出了 RITM,这是一个框架,其中中间件(而不是客户端、服务器或证书颁发机构)存储与吊销相关的数据。 RITM 提供了一种安全的撤销检查机制,可以保护用户隐私。我们还建议利用内容交付网络(CDN),并认为它们将构成一种快速且经济高效的传播撤销的方式。此外,RITM 使证书颁发机构对其发出的撤销负责,并且最大限度地减少了客户端和服务器的开销,因为它们既不必存储也不必下载任何消息。我们还描述了可行的部署模型,并对 RITM 进行了评估,以证明其在实际部署中的可行性和优势。
Although TLS is used on a daily basis by many critical applications, the public-key infrastructure that it relies on still lacks an adequate revocation mechanism. An ideal revocation mechanism should be inexpensive, efficient, secure, and privacypreserving. Moreover, rising trends in pervasive encryption pose new scalability challenges that a modern revocation system should address. In this paper, we investigate how network nodes can deliver certificate-validity information to clients. We present RITM, a framework in which middleboxes (as opposed to clients, servers, or certification authorities) store revocation-related data. RITM provides a secure revocation-checking mechanism that preserves user privacy. We also propose to take advantage of content-delivery networks (CDNs) and argue that they would constitute a fast and cost-effective way to disseminate revocations. Additionally, RITM keeps certification authorities accountable for the revocations that they have issued, and it minimizes overhead at clients and servers, as they have to neither store nor download any messages. We also describe feasible deployment models and present an evaluation of RITM to demonstrate its feasibility and benefits in a real-world deployment.