CertRevoke: a certificate revocation framework for named data networking
CertRevoke: a certificate revocation framework for named data networking
复制标题
DOI:
10.1145/3517212.3558079
复制
发表时间:
2022-09
期刊:
影响因子:
--
通讯作者:
Tianyuan Yu;Hongcheng Xie;Siqi Liu;Xinyv Ma;X. Jia;Lixia Zhang
中科院分区:
文献类型:
--
作者:
Tianyuan Yu;Hongcheng Xie;Siqi Liu;Xinyv Ma;X. Jia;Lixia Zhang
Named Data Networking (NDN) secures network communications by requiring all data packets to be signed upon production. This requirement makes usable and efficient NDN certificate issuance and revocation essential for NDN operations. In this paper, we first investigate and clarify core concepts related to NDN certificate revocation, then proceed with the design of CertRevoke, an NDN certificate revocation framework. CertRevoke utilizes naming conventions and trust schema to ensure certificate owners and issuers legitimately produce in-network cacheable records for revoked certificates. We evaluate the security properties and performance of CertRevoke through case studies. Our results show that deploying CertRevoke in an operational NDN network is feasible.