{"title":"Theoretical Analysis of Issuing Mechanism in Distributive Digital Certificate Revocation List","authors":"Jun Huang, Zhao Wang, Zhao Qiu, Mingrui Chen","doi":"10.1109/ICCEE.2008.74","DOIUrl":null,"url":null,"abstract":"The core of large-scale PKI (Public Key Infrastructure) is digital certificate, while in the service of certificate, the existing factors of password disclosure and expiration will lead to the certificate invalidation. Presently, PKI Administration always adopts the method of Certificate Revocation List ('CRL') to summarize the invalidation certificate. However, the biggest bottleneck of CRL application is the high peak value requirement rate for CRL storage, which will require the hardware unit with high performance but expensive price. The paper attempted to refine the CRL issuing mechanism in network structure based on the distributive concept of P2P network and then put forward a new issuing mechanism, distributive CRL issuing. Meanwhile, we took the theoretical analysis for it and the result has showed its advantages.","PeriodicalId":365473,"journal":{"name":"2008 International Conference on Computer and Electrical Engineering","volume":"8 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2008-12-20","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"9","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2008 International Conference on Computer and Electrical Engineering","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICCEE.2008.74","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 9
Abstract
The core of large-scale PKI (Public Key Infrastructure) is digital certificate, while in the service of certificate, the existing factors of password disclosure and expiration will lead to the certificate invalidation. Presently, PKI Administration always adopts the method of Certificate Revocation List ('CRL') to summarize the invalidation certificate. However, the biggest bottleneck of CRL application is the high peak value requirement rate for CRL storage, which will require the hardware unit with high performance but expensive price. The paper attempted to refine the CRL issuing mechanism in network structure based on the distributive concept of P2P network and then put forward a new issuing mechanism, distributive CRL issuing. Meanwhile, we took the theoretical analysis for it and the result has showed its advantages.