Hong-Sheng Huang, Cheng-Che Chuang, Jhih-Zen Shih, Hsuan-Tung Chen, Hung-Min Sun
{"title":"An Enhanced Online Certificate Status Protocol for Public Key Infrastructure with Smart Grid and Energy Storage System","authors":"Hong-Sheng Huang, Cheng-Che Chuang, Jhih-Zen Shih, Hsuan-Tung Chen, Hung-Min Sun","doi":"arxiv-2409.10929","DOIUrl":null,"url":null,"abstract":"The efficiency of checking certificate status is one of the key indicators in\nthe public key infrastructure (PKI). This prompted researchers to design the\nOnline Certificate Status Protocol (OCSP) standard, defined in RFC 6960, to\nguide developers in implementing OCSP components. However, as the environment\nincreasingly relies on PKI for identity authentication, it is essential to\nprotect the communication between clients and servers from rogue elements. This\ncan be achieved by using SSL/TLS techniques to establish a secure channel,\nallowing Certificate Authorities (CAs) to safely transfer certificate status\ninformation. In this work, we introduce the OCSP Stapling approach to optimize\nOCSP query costs in our smart grid environment. This approach reduces the\nnumber of queries from the Device Language Message Specification (DLMS) server\nto the OCSP server. Our experimental results show that OCSP stapling increases\nboth efficiency and security, creating a more robust architecture for the smart\ngrid.","PeriodicalId":501332,"journal":{"name":"arXiv - CS - Cryptography and Security","volume":"26 1","pages":""},"PeriodicalIF":0.0000,"publicationDate":"2024-09-17","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"arXiv - CS - Cryptography and Security","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/arxiv-2409.10929","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
Abstract
The efficiency of checking certificate status is one of the key indicators in
the public key infrastructure (PKI). This prompted researchers to design the
Online Certificate Status Protocol (OCSP) standard, defined in RFC 6960, to
guide developers in implementing OCSP components. However, as the environment
increasingly relies on PKI for identity authentication, it is essential to
protect the communication between clients and servers from rogue elements. This
can be achieved by using SSL/TLS techniques to establish a secure channel,
allowing Certificate Authorities (CAs) to safely transfer certificate status
information. In this work, we introduce the OCSP Stapling approach to optimize
OCSP query costs in our smart grid environment. This approach reduces the
number of queries from the Device Language Message Specification (DLMS) server
to the OCSP server. Our experimental results show that OCSP stapling increases
both efficiency and security, creating a more robust architecture for the smart
grid.