How to avoid the breakdown of public key infrastructures: forward secure signatures for certificate authorities

  • Johannes Braun
  • , Andreas Hülsing
  • , Alex Wiesmaier
  • , Martín A G Vigil
  • , Johannes Buchmann

Research output: Chapter in Book/Report/Conference proceedingConference contributionAcademicpeer-review

2 Citations (Scopus)

Abstract

Recent attacks and publications have shown the vulnerability of hierarchical Public Key Infrastructures (PKIs) and the fatal impact of revoked Certification Authority (CA) certificates in the PKIX validity model. Alternative validity models, such as the extended shell and the chain model, improve the situation but rely on independent proofs of existence, which are usually provided using time-stamps. As time-stamps are validated using certificates, they suffer from the same problems as the PKI they are supposed to protect. Our solution to this problem is abandoning time-stamps and providing proof of existence using Forward Secure Signatures (FSS). In particular, we present different possibilities to use the chain model together with FSS, resulting in schemes that include the necessary proofs of existence into the certificates themselves.

Original languageEnglish
Title of host publicationPublic Key Infrastructures, Services and Applications
Subtitle of host publication9th European Workshop, EuroPKI 2012, Pisa, Italy, September 13-14, 2012, Revised Selected Papers
EditorsS. De Capitani di Vimercati , Chr. Mitchell
Place of PublicationBerlin
PublisherSpringer
Pages53-68
Number of pages16
ISBN (Print)9783642400117
DOIs
Publication statusPublished - 2013
Externally publishedYes
Event9th European Workshop on Public Key Infrastructures, Services and Applications (EuroPKI 2012) - Pisa, Italy
Duration: 13 Sept 201214 Sept 2012
Conference number: 9

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume7868 LNCS
ISSN (Print)03029743
ISSN (Electronic)16113349

Conference

Conference9th European Workshop on Public Key Infrastructures, Services and Applications (EuroPKI 2012)
Abbreviated titleEuroPKI 2012
Country/TerritoryItaly
CityPisa
Period13/09/1214/09/12

Keywords

  • Authentication
  • CA
  • Certificate
  • Forward secure signature
  • PKI
  • Revocation
  • Time-stamping
  • Validity model

Fingerprint

Dive into the research topics of 'How to avoid the breakdown of public key infrastructures: forward secure signatures for certificate authorities'. Together they form a unique fingerprint.

Cite this