Cross-Certification Towards Distributed Authentication Infrastructure: A Case of Hyperledger Fabric

Cross-Certification Towards Distributed Authentication Infrastructure: A Case of Hyperledger Fabric
复制标题

DOI:
10.1109/access.2020.3011137
复制
发表时间:
2020-01-01
期刊:
影响因子:
3.9
通讯作者:
Saito, Shoichi
Saito, Shoichi
中科院分区:
计算机科学3区
文献类型:
--
作者:
Kakei, Shohei;Shiraishi, Yoshiaki;Saito, Shoichi

文献摘要

被引文献

相似文献

在物联网生态系统中,各种实体交易数据和数据分析结果,公钥基础设施在这些实体之间建立信任关系,指定谁信任谁的私钥方面发挥着重要作用。向私钥的所有者提供由代表受信任第三方的证书颁发机构(CA)颁发的公钥证书。虽然该证书通过验证数据源和防止拒绝交易来确保生态系统的可靠性,但它往往会导致信任过度集中在特定的CA上,因此,如果该CA受到侵犯,所有相关的信任关系都会受到损害。本文提出了一种称为元pki的分布式身份验证基础设施,通过多个ca执行的交叉认证过程来分散这种过度集中。虽然交叉认证能够建立相互信任的关系,但它不能以标准化的方式评估其他ca的可信度。因此,本文还提出了一种新的交叉认证方法,利用分布式账本技术建立基于统一标准的信任关系。它还描述了Hyperledger Fabric的元pki系统的实现,作为概念证明。一旦建立了信任关系,使用提议的系统验证它们大约需要65.7 ms,这是安全的,可以防止CA接管和外部攻击者的欺骗。
In Internet of Things ecosystems, where various entities trade data and data analysis results, public key infrastructure plays an important role in establishing trust relationships between these entities to specify who trusts whose private keys. The owner of a private key is provided with a public key certificate issued by a certificate authority (CA) representing a trusted third party. Although this certificate ensures the reliability of the ecosystem by verifying the data source and preventing the denial of trading, it often causes an overconcentration of trust in a particular CA. Consequently, if that CA is infringed, all the related trust relationships become compromised. The paper proposes a distributed authentication infrastructure called Meta-PKI that decentralizes such overconcentration via a cross-certification procedure performed by multiple CAs. Although cross-certification is capable of establishing mutual trust relationships, it does not evaluate the trustworthiness of other CAs in a standardized manner. Therefore, this paper also proposes a new cross-certification method using a distributed ledger technology for building trust relationships based on unified criteria. It also describes the implementation of a Meta-PKI system for Hyperledger Fabric as a proof of concept. Once trust relationships have been established, it takes approximately 65.7 ms to validate them using the proposed system, which is secure against CA takeover and spoofing by outsider attackers.