Using trusted responders in constrained aviation environments to reduce authentication overhead

计算机科学 证书 公钥基础设施 认证(法律) 计算机安全 公钥证书 公钥密码术 梅克尔树 证书颁发机构 架空(工程) 根证书 计算机网络 密码学 加密 操作系统 密码哈希函数 算法
作者
Jonathan Graefe,Laurent Léonardon,Mahmoud Esmael
标识
DOI:10.1109/icns58246.2023.10124308
摘要

This paper suggests a new authentication model using Online Certificate Status Protocol (OCSP) stapling with trusted responders to navigate a Public Key Infrastructure (PKI) trust tree in a constrained computing environment. This paper also suggests a model of how the trusted responders could be deployed and how to establish and maintain authentication between clients' applications and the trusted responder.Aircraft oftentimes work in limited RF bandwidth environments sharing a single frequency between many aircraft. Maximizing the efficiency of transmission time is paramount to servicing all aircraft communications needs. One of the large contributors to long transmission time in an IPS network is the login process, which requires the exchanging and verification of certificate chains. OCSP can be used to verify individual certificates, however it likely requires a request per certificate to the certificate authorities. Traditional OCSP responds with the validity information of a certificate, leaving the communicating counter parties, the constrained client and server, responsible for determining if the PKI tree between them is sufficiently strong to establish trust.The OCSP trusted responder model proposed by this paper would offload the PKI tree determination to trusted ground entities. The trusted ground entities would determine the level of trust, if any, for communication between the counter parties and forward only the necessary information for cryptographic exchange to the communicating counter parties. In an OCSP trusted responder model, a pre-configured list of trusted OCSP responders resides with the constrained client. During the authentication process the constrained client submits the list of OCSP trusted responders to the counter party server. The server is required to prove validity of its own PKI certificate using one of the OCSP trusted responders supplied by the client. The OCSP trusted responder would fetch any necessary intermediate certificates, walk the Public Key Infrastructure tree, and determine the level of trust, if any, between the counter parties and forward the information to the server. Thereby removing the need to exchange full certificate chains between constrained client and server. The server will then respond to the client with its own certificate, and the validation response from the OCSP trusted responder if any. The OCSP trusted responder model is adaptable and may be used in conjunction with, or in replace of, other verification methods of models.

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
乐乐应助luckzzz采纳,获得10
3秒前
9秒前
hi_traffic完成签到,获得积分10
9秒前
量子星尘发布了新的文献求助10
9秒前
12秒前
小乙猪完成签到 ,获得积分0
13秒前
sll完成签到 ,获得积分10
16秒前
文与武完成签到 ,获得积分10
18秒前
悄悄完成签到,获得积分10
22秒前
量子星尘发布了新的文献求助10
31秒前
卷心菜完成签到 ,获得积分10
35秒前
爱睡觉的杨先生完成签到 ,获得积分10
38秒前
李明完成签到 ,获得积分10
39秒前
mzrrong完成签到 ,获得积分10
40秒前
翁雁丝完成签到 ,获得积分10
41秒前
zzz完成签到 ,获得积分10
43秒前
48秒前
51秒前
57秒前
58秒前
Rolling完成签到 ,获得积分10
1分钟前
量子星尘发布了新的文献求助10
1分钟前
幸福完成签到 ,获得积分10
1分钟前
回忆应助武雨寒采纳,获得10
1分钟前
1分钟前
酷炫映阳完成签到 ,获得积分10
1分钟前
echo完成签到,获得积分10
1分钟前
wangsai0532完成签到,获得积分10
1分钟前
FF完成签到,获得积分10
1分钟前
量子星尘发布了新的文献求助10
1分钟前
shawn完成签到 ,获得积分10
1分钟前
嘟嘟嘟嘟嘟完成签到,获得积分10
1分钟前
奋斗的小研完成签到,获得积分10
1分钟前
耶耶完成签到,获得积分10
1分钟前
濮阳灵竹完成签到,获得积分10
1分钟前
量子星尘发布了新的文献求助10
1分钟前
婉孝完成签到,获得积分10
1分钟前
Sodagreen2023完成签到 ,获得积分10
1分钟前
1分钟前
cheong完成签到,获得积分10
1分钟前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
Encyclopedia of Reproduction Third Edition 3000
《药学类医疗服务价格项目立项指南(征求意见稿)》 1000
花の香りの秘密―遺伝子情報から機能性まで 800
1st Edition Sports Rehabilitation and Training Multidisciplinary Perspectives By Richard Moss, Adam Gledhill 600
Chemistry and Biochemistry: Research Progress Vol. 7 430
Biotechnology Engineering 400
热门求助领域 (近24小时)
化学 材料科学 生物 医学 工程类 计算机科学 有机化学 物理 生物化学 纳米技术 复合材料 内科学 化学工程 人工智能 催化作用 遗传学 数学 基因 量子力学 物理化学
热门帖子
关注 科研通微信公众号,转发送积分 5628787
求助须知:如何正确求助?哪些是违规求助? 4718375
关于积分的说明 14964910
捐赠科研通 4786643
什么是DOI,文献DOI怎么找? 2555951
邀请新用户注册赠送积分活动 1517087
关于科研通互助平台的介绍 1477841