Notification Services for the Server-Based Certificate Validation Protocol
نویسندگان
چکیده
The Server-Based Certificate Validation Protocol allows PKI clients to delegate to a server the construction or validation of certification paths. The protocol’s specification focuses on the communication between the server and the client and its security. It does not discuss how the servers can efficiently locate the necessary PKI resources like certificate or certificate revocation lists. In this paper we concentrate on this topic. We present a simple and effective method to facilitate locating and using various PKI resources by the servers, without modifying the protocol. We use the extension mechanism of the protocol for notifying the servers about PKI repositories, certificates, and revocations. We specify the tasks of the servers and certificate issuers and define the messages that are exchanged between them. A proof of concept is given by implementing an SCVP server, a client, and the proposed method in Java.
منابع مشابه
A Flexible Management Framework for Certificate Status Validation
Public key cryptography is widely recognized as the technology to develop and deploy authentication, integrity, confidentiality, and non-repudiation services. The services typical of public key cryptography requires a Public Key Infrastructure (PKI) in charge of securely managing keys/certificates for complex and large scale organizations. An essential PKI feature is the complete certificate st...
متن کاملUsing the Server-Based Certificate Validation Protocol (SCVP) to Convey Long-Term Evidence Records
Status of This Memo This document specifies an Internet standards track protocol for the Internet community, and requests discussion and suggestions for improvements. Please refer to the current edition of the "Internet Official Protocol Standards" (STD 1) for the standardization state and status of this protocol. Distribution of this memo is unlimited. Abstract The Server-based Certificate Val...
متن کاملInternet X.509 Public Key Infrastructure Data Validation and Certification Server Protocols
Status of this Memo This memo defines an Experimental Protocol for the Internet community. It does not specify an Internet standard of any kind. Discussion and suggestions for improvement are requested. Distribution of this memo is unlimited. Abstract This document describes a general Data Validation and Certification Server (DVCS) and the protocols to be used when communicating with it. The Da...
متن کاملAn Adaptive Authentication Protocol based on Reputation for Peer-to-Peer System
The services on the Internet were previously focused on the server-oriented system, but recently changed into a kind of distributed computing, peer-to-peer (simply P2P) systems which can be applied to instant messaging, collaborate computing, etc. Like a real face-to-face trust relationship, each peer with complicated trust relationship faced complex security problems. Especially, an authentica...
متن کاملThe Case for Prefetching and Prevalidating TLS Server Certificates
A key bottleneck in a full TLS handshake is the need to fetch and validate the server certificate before establishing a secure connection. We propose a mechanism by which a browser can prefetch and prevalidate server certificates so that by the time the user clicks on an HTTPS link, the server’s certificate is immediately ready to be used. Combining this with a recent proposal called Snap Start...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید
ثبت ناماگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید
ورودعنوان ژورنال:
- IJCNS
دوره 2 شماره
صفحات -
تاریخ انتشار 2009