ARECA: a highly attack resilient certification authority

SSRS '03 Pub Date : 2003-10-31 DOI:10.1145/1036921.1036927
Jiwu Jing, Peng Liu, D. Feng, Ji Xiang, Neng Gao, Jingqiang Lin
{"title":"ARECA: a highly attack resilient certification authority","authors":"Jiwu Jing, Peng Liu, D. Feng, Ji Xiang, Neng Gao, Jingqiang Lin","doi":"10.1145/1036921.1036927","DOIUrl":null,"url":null,"abstract":"Certification Authorities (CA) are a critical component of a PKI. All the certificates issued by a CA will become invalid when the (signing) private key of the CA is compromised. Hence it is a very important issue to protect the private key of an online CA. ARECA systems, built on top of threshold cryptography, ensure the security of a CA through a series of defense-in-depth protections. ARECA systems won't be compromised when a few system components are compromised or some system administrators betray. The private key of a CA is protected by distributing different shares of the key to different (signing) components and by ensuring that any component of the CA is unable to reconstruct the private key. In addition, the multi-layer system architecture of ARECA makes it very difficult to attack from outside. Several threshold-cryptography-based methods are proposed in the literature to construct an intrusion tolerant CA, and the uniqueness of ARECA is that it engineers a novel two phase signature composition scheme and a multi-layer CA protection architecture. As a result, ARECA is (a) practical, (b) highly resilient to both insider and outsider attacks that compromise one or more components, and (c) can prevent a variety of outside attacks.","PeriodicalId":414343,"journal":{"name":"SSRS '03","volume":"4 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2003-10-31","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"9","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"SSRS '03","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/1036921.1036927","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 9

Abstract

Certification Authorities (CA) are a critical component of a PKI. All the certificates issued by a CA will become invalid when the (signing) private key of the CA is compromised. Hence it is a very important issue to protect the private key of an online CA. ARECA systems, built on top of threshold cryptography, ensure the security of a CA through a series of defense-in-depth protections. ARECA systems won't be compromised when a few system components are compromised or some system administrators betray. The private key of a CA is protected by distributing different shares of the key to different (signing) components and by ensuring that any component of the CA is unable to reconstruct the private key. In addition, the multi-layer system architecture of ARECA makes it very difficult to attack from outside. Several threshold-cryptography-based methods are proposed in the literature to construct an intrusion tolerant CA, and the uniqueness of ARECA is that it engineers a novel two phase signature composition scheme and a multi-layer CA protection architecture. As a result, ARECA is (a) practical, (b) highly resilient to both insider and outsider attacks that compromise one or more components, and (c) can prevent a variety of outside attacks.
ARECA:具有高度抗攻击能力的证书颁发机构
证书颁发机构(CA)是PKI的关键组成部分。当CA的(签名)私钥泄露时,CA颁发的所有证书都将失效。因此,如何保护在线CA的私钥是一个非常重要的问题。建立在阈值密码学基础上的ARECA系统,通过一系列的纵深防御来保证CA的安全。当一些系统组件被破坏或一些系统管理员背叛时,ARECA系统不会受到损害。通过将密钥的不同共享分发给不同的(签名)组件,并确保CA的任何组件都无法重构私钥,CA的私钥得到了保护。此外,ARECA的多层体系结构使得从外部攻击非常困难。文献中提出了几种基于阈值密码学的方法来构建入侵容忍CA,而ARECA的独特之处在于它设计了一种新颖的两阶段签名组合方案和多层CA保护体系结构。因此,ARECA具有(a)实用性,(b)对危及一个或多个组件的内部和外部攻击具有高度弹性,以及(c)可以防止各种外部攻击。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信