Reducing the cost of certificate revocation: A case study

Mona H. Ofigsbø, Stig Frode Mjølsnes, Poul Heegaard, Leif Nilsen

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

5 Scopus citations

Abstract

We investigate how to reduce the cost of certificate revocation in the PKI system of UNINETT (The Internet of Norwegian Universities and Colleges), by analyzing and characterizing existing users' needs and behavior. The focus is on how to reduce the number of revoked certificates and bandwidth consumption in order to achieve better scalability. We distinguish between three main types of revocation mechanisms: list pull, list push, and short validity period. We try to find the optimal parameter values with respect to revocation method, the number of groups, group size, validity period duration, application type access, and certificate security policy. The current user categories are permanent employees, temporary employees and students. This paper analyzes the collected empirical data for how long the users actually stay in the system, and the reasons and frequency of user terminations that require certificate revocations, and then models the consequences for certificate revocation.

Original languageEnglish
Title of host publicationPublic Key Infrastructures, Services and Applications - 6th European Workshop, EuroPKI 2009, Revised Selected Papers
Pages51-66
Number of pages16
DOIs
StatePublished - 2010
Externally publishedYes
Event6th European Workshop on Public Key Services, Applications and Infrastructures, EuroPKI 2009 - Pisa, Italy
Duration: 10 Sep 200911 Sep 2009

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume6391 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference6th European Workshop on Public Key Services, Applications and Infrastructures, EuroPKI 2009
Country/TerritoryItaly
CityPisa
Period10/09/0911/09/09

Keywords

  • Revocation schemes
  • architecture
  • network aspects
  • policies
  • scalability

Fingerprint

Dive into the research topics of 'Reducing the cost of certificate revocation: A case study'. Together they form a unique fingerprint.

Cite this