• DocumentCode
    2507416
  • Title

    On the Tradeoff between Performance and Security in OCSP-Based Certificate Revocation Systems for Wireless Environments

  • Author

    Berbecaru, Diana

  • Author_Institution
    Politecnico di Torino, Italy
  • fYear
    2006
  • fDate
    26-29 June 2006
  • Firstpage
    340
  • Lastpage
    346
  • Abstract
    The Online Certificate Status Protocol (OCSP) specifies a mechanism used to determine the status of public-key certificates (PKC). OCSP deployments have been used so far to ensure timely and secure certificate status information for high-value electronic transactions, like in the banking environments. Nevertheless, since an OCSP responder operates always online it could be subject to the key exposure attack (problem). A solution to the last problem is given by the forward secure signature (FSS) schemes. This paper investigates various modifications of the OCSP-based certificate revocation systems for wireless environments using efficient generic FSS schemes, i.e. Bellare-Minner tree, the Iterated Sum construction and the MMM scheme. In the proposed systems we evaluate the tradeoff between the performance (i.e. response size and amount of computation required) and security (vulnerability to forgery).
  • Keywords
    Bandwidth; Banking; Communication system security; Data structures; Environmental management; Forgery; Frequency selective surfaces; Protocols; Public key; Public key cryptography;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computers and Communications, 2006. ISCC '06. Proceedings. 11th IEEE Symposium on
  • ISSN
    1530-1346
  • Print_ISBN
    0-7695-2588-1
  • Type

    conf

  • DOI
    10.1109/ISCC.2006.114
  • Filename
    1691052