Accountable key infrastructure (AKI): a proposal for a public-key validation infrastructure

WWW(2013)

引用 201|浏览184
暂无评分
摘要
Recent trends in public-key infrastructure research explore the tradeoff between decreased trust in Certificate Authorities (CAs), resilience against attacks, communication overhead (bandwidth and latency) for setting up an SSL/TLS connection, and availability with respect to verifiability of public key information. In this paper, we propose AKI as a new public-key validation infrastructure, to reduce the level of trust in CAs. AKI integrates an architecture for key revocation of all entities (e.g., CAs, domains) with an architecture for accountability of all infrastructure parties through checks-and-balances. AKI efficiently handles common certification operations, and gracefully handles catastrophic events such as domain key loss or compromise. We propose AKI to make progress towards a public-key validation infrastructure with key revocation that reduces trust in any single entity.
更多
查看译文
关键词
public-key validation infrastructure,accountable key infrastructure,infrastructure party,catastrophic event,certificate authorities,public key information,key revocation,public-key infrastructure research,new public-key validation infrastructure,domain key loss,tls connection
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要