GI LogoGI Logo
  • Anmelden
Digitale Bibliothek
    • Gesamter Bestand

      • Bereiche & Sammlungen
      • Titel
      • Autor
      • Erscheinungsdatum
      • Schlagwort
    • Diese Sammlung

      • Titel
      • Autor
      • Erscheinungsdatum
      • Schlagwort
Digital Bibliothek der Gesellschaft für Informatik e.V.
GI-DL
    • English
    • Deutsch
  • Deutsch 
    • English
    • Deutsch
Dokumentanzeige 
  •   Startseite
  • Lecture Notes in Informatics
  • Proceedings
  • Open Identity Summit
  • P293 - Open Identity Summit 2019
  • Dokumentanzeige
JavaScript is disabled for your browser. Some features of this site may not work without it.
  •   Startseite
  • Lecture Notes in Informatics
  • Proceedings
  • Open Identity Summit
  • P293 - Open Identity Summit 2019
  • Dokumentanzeige

Let’s Revoke! Mitigating Revocation Equivocation by re-purposing the Certificate Transparency Log

Autor(en):
Mueller, Tobias [DBLP] ;
Stübs, Marius [DBLP] ;
Federrath, Hannes [DBLP]
Zusammenfassung
Distributing cryptographic keys and asserting their validity is a challenge for any system relying on such keys, for example the World Wide Web with HTTPS or OpenPGP encrypted email. When keys get stolen or compromised, it is desirable to shorten the time during which an attacker can decrypt or sign messages. This is usually achieved by revoking the affected certificates. We investigate the security requirements for distributing key revocations in the context of asynchronous decentralised messaging and analyse the status quo with respect to these requirements. We show that equivocation, integrity protection, and non-repudiation pose a challenge in today’s revocation distribution infrastructure. We find that a publicly verifiable append-only data structure serves our purpose and notice that operating such an infrastructure is expensive. We propose a revocation distribution scheme that fulfils our requirements. Our scheme uses the already existing Certificate Transparency (CT) logs of the WebPKI as a publicly verifiable append-only data structure for storing revocations through specially crafted TLS certificates. The security of our system largely stems from the properties of these CT logs. Additionally, we analyse the computational and bandwidth requirements of our scheme and show limitations of the protocol we propose.
  • Vollständige Referenz
  • BibTeX
Mueller, T., Stübs, M. & Federrath, H., (2019). Let’s Revoke! Mitigating Revocation Equivocation by re-purposing the Certificate Transparency Log. In: Roßnagel, H., Wagner, S. & Hühnlein, D. (Hrsg.), Open Identity Summit 2019. Gesellschaft für Informatik, Bonn. (S. 143-154).
@inproceedings{mci/Mueller2019,
author = {Mueller, Tobias AND Stübs, Marius AND Federrath, Hannes},
title = {Let’s Revoke! Mitigating Revocation Equivocation by re-purposing the Certificate Transparency Log},
booktitle = {Open Identity Summit 2019},
year = {2019},
editor = {Roßnagel, Heiko AND Wagner, Sven AND Hühnlein, Detlef} ,
pages = { 143-154 },
publisher = {Gesellschaft für Informatik, Bonn},
address = {}
}
DateienGroesseFormatAnzeige
proceedings-12.pdf1.896Mb PDF Öffnen

Haben Sie fehlerhafte Angaben entdeckt? Sagen Sie uns Bescheid: Feedback abschicken

Mehr Information

ISBN: 978-3-88579-687-9
ISSN: 1617-5468
Datum: 2019
Sprache: en (en)

Keywords

  • key revocation
  • asynchronous decentralised messaging
  • email
  • PKI
  • trust
  • OpenPGP
Sammlungen
  • P293 - Open Identity Summit 2019 [19]

Zur Langanzeige


Über uns | FAQ | Hilfe | Impressum | Datenschutz

Gesellschaft für Informatik e.V. (GI), Kontakt: Geschäftsstelle der GI
Diese Digital Library basiert auf DSpace.

 

 


Über uns | FAQ | Hilfe | Impressum | Datenschutz

Gesellschaft für Informatik e.V. (GI), Kontakt: Geschäftsstelle der GI
Diese Digital Library basiert auf DSpace.