• DocumentCode
    2088164
  • Title

    An efficient, dynamic and trust preserving public key infrastructure

  • Author

    Levi, Albert ; Caglayan, M. Ufuk

  • Author_Institution
    Dept. of Comput. Eng., Bogazici Univ., Istanbul, Turkey
  • fYear
    2000
  • fDate
    2000
  • Firstpage
    203
  • Lastpage
    214
  • Abstract
    Nested certification is a methodology for efficient certificate path verification. Nested certificates can be used together with classical certificates in the Public Key Infrastructures (PKIs). Such a PKI, which is called nested certificate based PKI (NPKI), is proposed as an alternative to classical PKI. The NPKI formation model is a transition from an existing PKI by issuing nested certificates. Thus, we can extract efficiently verifiable nested certificate paths instead of classical certificate paths. NPKI is a dynamic system and involves several authorities in order to add a new user to the system. This uses the authorities´ idle time to the benefit of the verifiers. We analyze the trade-off between the nested certification overhead and the time improvement on the certificate path verification. This trade-off is acceptable in order to generate quickly verifiable certificate paths. Moreover, PKI-to-NPKI transition preserves the existing hierarchy and trust relationships in the PKI, so that it can be used for strictly hierarchical PKIs
  • Keywords
    authorisation; certification; public key cryptography; NPKI formation model; PKI-to-NPKI transition; Public Key Infrastructures; certificate path verification; classical certificate paths; dynamic system; nested certificate based PKI; nested certification; nested certification overhead; strictly hierarchical PKIs; trust preserving public key infrastructure; trust relationships; verifiable certificate paths; verifiable nested certificate paths; Certification; Content addressable storage; Hip; ISO standards; Internet; Postal services; Privacy; Public key; Public key cryptography; Tellurium;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Security and Privacy, 2000. S&P 2000. Proceedings. 2000 IEEE Symposium on
  • Conference_Location
    Berkeley, CA
  • ISSN
    1081-6011
  • Print_ISBN
    0-7695-0665-8
  • Type

    conf

  • DOI
    10.1109/SECPRI.2000.848458
  • Filename
    848458