Seventh IEEE Symposium on Computers and Communications (ISCC'02)
A Flexible Scheme for On-Line Public-Key Certificate Status Updating and Verification
Ramada Hotel, Taormina-Giardini Naxos, Italy
July 01-July 04
ISBN: 0-7695-1671-8
A new on-line method for efficient handling of certificates within Public-Key Infrastructures (PKIs) is presented. The method is based on a purposely-conceived extension of the One-Way Accumulator (OWA) cryptographic primitive, which permits to provide an explicit, concise, authenticated and not forgeable information about the revocation status of each certificate. A thorough investigation on the performance attainable shows that the devised method exhibits the same positive features of the well-known On-line Certificate Status Protocol (OCSP) as regards scalability, security and timeliness. Moreover, its peculiar characteristic of collectively authenticate via a single directory-signed proof the status of all the certificates handled within a PKI leads to a significant reduction of the directory computational load that, in a high-traffic context, could be nearly unbearable when OCSP is applied.