Leveraging locality of reference for certificate revocation
Leveraging locality of reference for certificate revocation
复制标题
利用引用位置进行证书吊销
DOI:
10.1145/3359789.3359819
复制
发表时间:
2019
期刊:
影响因子:
--
通讯作者:
Seamons, Kent
中科院分区:
文献类型:
--
作者:
Dickinson, Luke;Smith, Trevor;Seamons, Kent
X.509 certificate revocation defends against man-in-the-middle attacks involving a compromised certificate. Certificate revocation strategies face scalability, effectiveness, and deployment challenges as HTTPS adoption rates have soared. We propose Certificate Revocation Table (CRT), a new revocation strategy that is competitive with or exceeds alternative state-of-the-art solutions in effectiveness, efficiency, certificate growth scalability, mass revocation event scalability, revocation timeliness, privacy, and deployment requirements. The CRT design assumes that locality of reference applies to the certificates accessed by an organization. The CRT periodically checks the revocation status of X.509 certificates recently used by the organization. Pre-checking the revocation status of certificates the clients are likely to use avoids the security problems of on-demand certificate revocation checking.To validate both the effectiveness and efficiency of our approach, we simulated a CRT using 60 days of TLS traffic logs from Brigham Young University to measure the effects of actively refreshing revocation status information for various certificate working set window lengths. A working set window size of 45 days resulted in an average of 99.86% of the TLS handshakes having revocation information cached in advance. The CRT storage requirements are small. The initial revocation status information requires downloading a 6.7 MB file, and subsequent updates require only 205.1 KB of bandwidth daily. Updates that include only revoked certificates require just 215 bytes of bandwidth per day.
登录
查看更多内容
DOI:
--
发表时间:
2010
期刊:
影响因子:
--
作者:
Adam Langley
通讯作者:
Adam Langley
DOI:
--
发表时间:
2016-10
期刊:
--
影响因子:
--
作者:
Mark O'Neill;S. Heidbrink;Scott Ruoti;Jordan Whitehead;Dan Bunker;Luke Dickinson;Travis Hendershot;J. Reynolds;K. Seamons;D. Zappala
通讯作者:
Mark O'Neill;S. Heidbrink;Scott Ruoti;Jordan Whitehead;Dan Bunker;Luke Dickinson;Travis Hendershot;J. Reynolds;K. Seamons;D. Zappala
DOI:
10.17487/rfc7633
发表时间:
2015-10
期刊:
RFC
影响因子:
--
作者:
P. Hallam-Baker
通讯作者:
P. Hallam-Baker
DOI:
10.1109/icdcs.2016.91
发表时间:
2016
期刊:
2016 IEEE 36th International Conference on Distributed Computing Systems (ICDCS)
影响因子:
--
作者:
Pawel Szalachowski;L. Chuat;Taeho Lee;A. Perrig
通讯作者:
A. Perrig
DOI:
10.1109/compsac.2017.240
发表时间:
2017
期刊:
2017 IEEE 41st Annual Computer Software and Applications Conference (COMPSAC)
影响因子:
--
作者:
A. Wazan;R. Laborde;D. Chadwick;F. Barrère;A. Benzekri
通讯作者:
A. Benzekri