Shared generation of random number with timestamp: How to cope with the leakage of the CA’s secret

0Citations
Citations of this article
30Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Public-key certificates play an important role in a public-key cryptosystem. In a public-key infrastructure, it is a presupposition that only the issuer of a signature knows the signing key. Since the security of all clients of the CA depends on the secrecy of the CA’s signing-key, CA’s will pose an attractive target for break-ins[1][2]. Once there is a leakage of information on the signing key, the whole system has to be reconstructed as quickly as possible in order to prevent the spread of damage. However, it requires a long time to reconstruct all certificates, because it involves large computation and communication. In this paper, we present a practical solution to cope with the leakage of the CA’s signing-key. In our protocol, two random number generators (RNG) generate distinct random numbers, and combine them to a random number utilized in the signature algorithm and the timestamp which cannot be forged without revealing the secret of both RNG. A verifier can check the timestamp and verify validity and time when the random number has been generated. That is, it is impossible for adversaries to forge arbitrary certificates without revealing the secret of both RNGs. We show a concrete protocol suitable for a digital signature scheme based on the discrete logarithm.

Cite

CITATION STYLE

APA

Watanabe, Y., & Imai, H. (1999). Shared generation of random number with timestamp: How to cope with the leakage of the CA’s secret. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 1560, pp. 290–305). Springer Verlag. https://doi.org/10.1007/3-540-49162-7_23

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free