Accountable key infrastructure (AKI): a proposal for a public-key validation infrastructure

Accountable key infrastructure (AKI): a proposal for a public-key validation infrastructure
复制标题

负责任的密钥基础设施(AKI):公钥验证基础设施的提案

DOI:
--
复制
发表时间:
2013
期刊:
The Web Conference
影响因子:
--
通讯作者:
Virgil D. Gligor
Virgil D. Gligor
中科院分区:
--
文献类型:
--
作者:
T. Kim;Lin;A. Perrig;Collin Jackson;Virgil D. Gligor

文献摘要

被引文献

相似文献

公钥基础设施研究的最新趋势探讨了证书颁发机构(ca)信任度降低、抵御攻击的弹性、建立SSL/TLS连接的通信开销(带宽和延迟)以及公钥信息可验证性方面的可用性之间的权衡。在本文中,我们提出AKI作为一种新的公钥验证基础设施,以降低ca的信任水平。AKI集成了一个用于所有实体(例如,ca,域)的密钥撤销的体系结构,以及一个通过制衡对所有基础设施各方负责的体系结构。AKI有效地处理常见的认证操作,并优雅地处理灾难性事件,如域密钥丢失或泄露。我们建议AKI在公钥验证基础设施方面取得进展,该基础设施具有密钥撤销功能,可以降低对任何单个实体的信任。
Recent trends in public-key infrastructure research explore the tradeoff between decreased trust in Certificate Authorities (CAs), resilience against attacks, communication overhead (bandwidth and latency) for setting up an SSL/TLS connection, and availability with respect to verifiability of public key information. In this paper, we propose AKI as a new public-key validation infrastructure, to reduce the level of trust in CAs. AKI integrates an architecture for key revocation of all entities (e.g., CAs, domains) with an architecture for accountability of all infrastructure parties through checks-and-balances. AKI efficiently handles common certification operations, and gracefully handles catastrophic events such as domain key loss or compromise. We propose AKI to make progress towards a public-key validation infrastructure with key revocation that reduces trust in any single entity.