loading...
 This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
11th IEEE Symposium on Computers and Communications (ISCC'06)
On the Tradeoff between Performance and Security in OCSP-Based Certificate Revocation Systems for Wireless Environments
Cagliari, Sardinia, Italy
June 26-June 29
ISBN: 0-7695-2588-1
Diana Berbecaru, Politecnico di Torino, Italy
The Online Certificate Status Protocol (OCSP) specifies a mechanism used to determine the status of public-key certificates (PKC). OCSP deployments have been used so far to ensure timely and secure certificate status information for high-value electronic transactions, like in the banking environments. Nevertheless, since an OCSP responder operates always online it could be subject to the key exposure attack (problem). A solution to the last problem is given by the forward secure signature (FSS) schemes. This paper investigates various modifications of the OCSP-based certificate revocation systems for wireless environments using efficient generic FSS schemes, i.e. Bellare-Minner tree, the Iterated Sum construction and the MMM scheme. In the proposed systems we evaluate the tradeoff between the performance (i.e. response size and amount of computation required) and security (vulnerability to forgery).
Citation:
Diana Berbecaru, "On the Tradeoff between Performance and Security in OCSP-Based Certificate Revocation Systems for Wireless Environments," iscc, pp.340-346, 11th IEEE Symposium on Computers and Communications (ISCC'06), 2006
Usage of this product signifies your acceptance of the Terms of Use.