• DocumentCode
    1707340
  • Title

    A new on-line certificate validation method using LDAP component matching technology

  • Author

    Choi, Jong Hyuk ; Lim, Sang Seok ; Zeilenga, Kurt D.

  • Author_Institution
    IBM T. J. Watson Res. Center, Yorktown Heights, NY, USA
  • fYear
    2005
  • Firstpage
    280
  • Lastpage
    285
  • Abstract
    This paper presents a new on-line certificate validation method which provides higher degree of security, scalability, and interoperability than do the pre-existing approaches. It combines two basic data structures for certificate revocation, certificate revocation list (CRL) and the authenticated dictionary such as certificate revocation tree (CRT), into a single framework by utilizing the component matching enabled lightweight directory access protocol (LDAP) service. With the new method, end entities that want to check the validity of certificates can request an extended LDAP search operation with a component matching assertion against all revoked certificate components in a CRL and check whether a revoked certificate having the asserted serial number is found. In order to ensure strong security without requiring trusted directories, CRLs are represented as an authenticated dictionary when decoded from distinguished encoding rules (DER) to an internal ASN.1 representation. The information required to construct the authenticated dictionary is conveyed from the certificate authority (CA) via a new CRL extension. The proposed method facilitates a number of advantages over the previous approaches like online certificate status protocol (OCSP): 1) it enables higher security because it does not require trusted entities other than the CA such as trusted LDAP servers and trusted OCSP responders; 2) it improves scalability and performance because it does not require responses to be signed as in OCSP; 3) it can intemperate well with the existing CRL framework; and 4) it does not need support for additional protocols for on-line certificate validation because it is built on LDAP which is the main access method to download CRLs. The proposed method can also be used as a CRL back-end of OCSP to offload CRL management and to enhance its trust model.
  • Keywords
    access protocols; certification; data structures; message authentication; open systems; public key cryptography; LDAP component matching; LDAP search operation; OCSP; authenticated dictionary; certificate revocation list; certificate revocation tree; data structure; distinguished encoding rules; internal ASN.1 representation; interoperability; lightweight directory access protocol; online certificate status protocol; online certificate validation; public key infrastructure; scalability; security; trust model; Access protocols; Cathode ray tubes; Data security; Decoding; Density estimation robust algorithm; Dictionaries; Encoding; Information security; Scalability; Tree data structures;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Assurance Workshop, 2005. IAW '05. Proceedings from the Sixth Annual IEEE SMC
  • Print_ISBN
    0-7803-9290-6
  • Type

    conf

  • DOI
    10.1109/IAW.2005.1495964
  • Filename
    1495964