Skip to main content

Distributed Storage and Revocation in Digital Certificate Databases

  • Conference paper
  • First Online:

Part of the book series: Lecture Notes in Computer Science ((LNCS,volume 1873))

Abstract

Public-key cryptography is fast becoming the foundation for those applications that require security and authentication in open networks. But the widespread use of a global public-key cryptosystem requires that public-key certificates are always available and up-to-date. Problems associated to digital certificates management, like storage, retrieval, maintenance, and, specially, revocation, require special procedures that ensure reliable features because of the critical significance of inaccuracies. Most of the existing systems use a Certificate Revocation List, a repository of certificates that have been revoked before their expiration date. The need to access CRLs in order to check certificate revocations becomes a performance handicap. Furthermore, they introduce a source of vulnerability in the whole security infrastructure, as it is impossible to produce a new CRL each time a revocation takes place. This paper introduces an alternative for the storage of digital certificates that avoids the use of CRLs. The system is designed to provide a distributed management of digital certificates by using Certification Authorities that, while being part of a whole Public-Key Infrastructure, operate over local certificates databases. Communication protocols between local databases have been designed to minimize network traffic without a lack of security and efficiency.

This is a preview of subscription content, log in via an institution.

Buying options

Chapter
USD   29.95
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
eBook
USD   84.99
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
Softcover Book
USD   109.99
Price excludes VAT (USA)
  • Compact, lightweight edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Purchases are for personal use only

Learn about institutional subscriptions

Preview

Unable to display preview. Download preview PDF.

Unable to display preview. Download preview PDF.

References

  1. W. Diffie, M. Hellman, ”New Directions in Cryptography”, IEEE Transactions on Information Theory. IT-22, n. 6. 1976, pp. 644–654.

    Article  MathSciNet  Google Scholar 

  2. IlpfWorking Group on Certification Authority Practices, ” The Role of Certification Authorities in Consumer Transactions”, Internet Law and Policy Forum, 1997.

    Google Scholar 

  3. ISO International Standard 9594, ” Information Technology-Open Systems Interconnection Reference Model: The Directory”, 1988.

    Google Scholar 

  4. W. Ford, M. Baum, ” Secure Electronic Commerce”, Prentice-Hall, 1997.

    Google Scholar 

  5. International Telecommunication Union, Itu-t recommendation x.509, ” Information technology-Open Systems Interconnection-The Directory: Authentication Framework”, 1997.

    Google Scholar 

  6. P. Mockapetris, ” DNS Encoding of Network Names and Other Types”, Request for Comment 1101, 1989.

    Google Scholar 

  7. D. Eastlake, C. Kaufman, ” Domain Name System Security Extensions”, Request for Comment 2065, 1997.

    Google Scholar 

  8. D. Eastlake, ” Secure Domain Name System Dynamic Update”, Request for Comment 2137, 1997.

    Google Scholar 

  9. European Commission, ” Proposal for a European Parliament and Council Directive on a Common Framework for Electronic Signatures”, COM(1998) 297 final, 1998.

    Google Scholar 

  10. J. Lopez, A. Mana, J. Ortega, J. M. Troya, ” Cert’eM: Certification System Based on Electronic Mail Service Structure”, Secure Networking-CQRE’99, LNCS 1740, Springer, 1999.

    Google Scholar 

  11. A. Mana, F. Villalba, J. Lopez, ” Secure Examinations Through The Internet”, Proceedings of Teleteaching’98, IFIP World Computer Congress, 1998.

    Google Scholar 

Download references

Author information

Authors and Affiliations

Authors

Editor information

Editors and Affiliations

Rights and permissions

Reprints and permissions

Copyright information

© 2000 Springer-Verlag Berlin Heidelberg

About this paper

Cite this paper

Lopez, J., Mana, A., Ortega, J.J., Troya, J.M. (2000). Distributed Storage and Revocation in Digital Certificate Databases. In: Ibrahim, M., Küng, J., Revell, N. (eds) Database and Expert Systems Applications. DEXA 2000. Lecture Notes in Computer Science, vol 1873. Springer, Berlin, Heidelberg. https://doi.org/10.1007/3-540-44469-6_87

Download citation

  • DOI: https://doi.org/10.1007/3-540-44469-6_87

  • Published:

  • Publisher Name: Springer, Berlin, Heidelberg

  • Print ISBN: 978-3-540-67978-3

  • Online ISBN: 978-3-540-44469-5

  • eBook Packages: Springer Book Archive

Publish with us

Policies and ethics