An approach for evaluating trust in X.509 certificates

An approach for evaluating trust in X.509 certificates
复制标题

评估 X.509 证书信任度的方法

DOI:
--
复制
发表时间:
2016
期刊:
International Conference for Internet Technology and Secured Transactions
影响因子:
--
通讯作者:
H. Bakkali
H. Bakkali
中科院分区:
--
文献类型:
--
作者:
Zakia El Uahhabi;H. Bakkali

文献摘要

被引文献

相似文献

如今,X.509证书主要用于实体的身份验证。这些组织和人们使用它来确认其在线交易中的身份。然后,有必要验证证书可信度,以接受或拒绝特定交易。此外,证书是根据证书政策中描述的程序颁发证书的。这些程序中的任何缺陷都可能影响证书当局的信任度,这会使该机构签署的证书缺乏信任。在这种情况下,依赖各方需要一种自动机制来评估受到疑问的信任证书水平。在本文中,我们授予他们这种机制,以获取有关其可信度的信息。实际上,我们提出了一个信任框架架构,该体系结构由信任级计算中涉及的几个组件组成。然后,我们建议一种基于计算出的CA信托级别的三个参数,证书策略中指定的过程质量以及分配给认证字段内容的评级。我们提出的解决方案允许依靠各方就证书可信度做出决定。
Today, X.509 certificates is largely adopted for the identity verification of an entity. Such organizations and people use it to confirm their identities in online transaction. Then, it is necessary to verify the certificate trustworthiness in order to accept or reject it for a particular transaction. Besides, certificates are issued by the certificate authority based on the procedures which are described in a certificate policy. Any deficiency in these procedures may influence a certificate authority trustworthiness, which creates a trust lack in the certificates signed by this authority. In this context, relying parties need an automated mechanism to evaluate a trust level of certificate which come into question. In this paper, we grant them this mechanism to have information about its trustworthiness. In fact, we propose a trust framework architecture which is composed from the several components involved in the trust level calculation. Then, we suggest a trust level calculation algorithm which is based on three parameters that are the calculated CA trust level, the quality of procedures indicated in the certificate policy and the rating assigned to certification fields content. Our proposed solution allows relying parties to make a decision about certificate trustworthiness.