Certificate Revocation Guard (CRG): An Efficient Mechanism for Checking Certificate Revocation

12Citations
Citations of this article
5Readers
Mendeley users who have this article in their library.
Get full text

Abstract

In the Public Key infrastructure (PKI) model, digital certificates play a vital role in securing online communication. Communicating parties exchange and validate these certificates, the validation fails if a certificate has been revoked. In this paper we propose the Certificate Revocation Guard (CRG) to efficiently check certificate revocation while minimising bandwidth, latency and storage overheads. CRG is based on OCSP, which caches the status of certificates locally. CRG could be installed on the user's machine, at the organisational proxy or even at the ISP level. Compared to a naive approach (where a client checks the revocation status of all certificates in the chain on every request), CRG decreases the bandwidth overheads and network latencies by 95%. Using CRG incurs 69% lower storage overheads compared to the CRL method. Our results demonstrate the effectiveness of our approach to improve certificate revocation.

Cite

CITATION STYLE

APA

Hu, Q., Asghar, M. R., & Brownlee, N. (2016). Certificate Revocation Guard (CRG): An Efficient Mechanism for Checking Certificate Revocation. In Proceedings - Conference on Local Computer Networks, LCN (pp. 527–530). IEEE Computer Society. https://doi.org/10.1109/LCN.2016.84

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free