Using trusted responders in constrained aviation environments to reduce authentication overhead

计算机科学 证书 公钥基础设施 认证(法律) 计算机安全 公钥证书 公钥密码术 梅克尔树 证书颁发机构 架空(工程) 根证书 计算机网络 密码学 加密 操作系统 密码哈希函数 算法
作者
Jonathan Graefe,Laurent Léonardon,Mahmoud Esmael
标识
DOI:10.1109/icns58246.2023.10124308
摘要

This paper suggests a new authentication model using Online Certificate Status Protocol (OCSP) stapling with trusted responders to navigate a Public Key Infrastructure (PKI) trust tree in a constrained computing environment. This paper also suggests a model of how the trusted responders could be deployed and how to establish and maintain authentication between clients' applications and the trusted responder.Aircraft oftentimes work in limited RF bandwidth environments sharing a single frequency between many aircraft. Maximizing the efficiency of transmission time is paramount to servicing all aircraft communications needs. One of the large contributors to long transmission time in an IPS network is the login process, which requires the exchanging and verification of certificate chains. OCSP can be used to verify individual certificates, however it likely requires a request per certificate to the certificate authorities. Traditional OCSP responds with the validity information of a certificate, leaving the communicating counter parties, the constrained client and server, responsible for determining if the PKI tree between them is sufficiently strong to establish trust.The OCSP trusted responder model proposed by this paper would offload the PKI tree determination to trusted ground entities. The trusted ground entities would determine the level of trust, if any, for communication between the counter parties and forward only the necessary information for cryptographic exchange to the communicating counter parties. In an OCSP trusted responder model, a pre-configured list of trusted OCSP responders resides with the constrained client. During the authentication process the constrained client submits the list of OCSP trusted responders to the counter party server. The server is required to prove validity of its own PKI certificate using one of the OCSP trusted responders supplied by the client. The OCSP trusted responder would fetch any necessary intermediate certificates, walk the Public Key Infrastructure tree, and determine the level of trust, if any, between the counter parties and forward the information to the server. Thereby removing the need to exchange full certificate chains between constrained client and server. The server will then respond to the client with its own certificate, and the validation response from the OCSP trusted responder if any. The OCSP trusted responder model is adaptable and may be used in conjunction with, or in replace of, other verification methods of models.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
更新
大幅提高文件上传限制,最高150M (2024-4-1)

科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
2秒前
151发布了新的文献求助10
3秒前
yuyu完成签到,获得积分10
4秒前
文艺鞋垫完成签到,获得积分10
4秒前
5秒前
hui发布了新的文献求助10
6秒前
TCMning发布了新的文献求助10
8秒前
shweah2003完成签到,获得积分10
8秒前
9秒前
任性星星完成签到 ,获得积分10
9秒前
11秒前
happy123完成签到,获得积分10
11秒前
ok发布了新的文献求助10
15秒前
快乐小王完成签到 ,获得积分10
16秒前
hhhzzy完成签到 ,获得积分10
18秒前
锤子阿完成签到 ,获得积分10
19秒前
20秒前
坚强的纸飞机完成签到,获得积分10
22秒前
ZZZ完成签到,获得积分10
22秒前
23秒前
martiniwine完成签到 ,获得积分10
25秒前
可乐发布了新的文献求助10
26秒前
风中梦蕊完成签到 ,获得积分10
27秒前
28秒前
酷波er应助哭泣老三采纳,获得10
29秒前
杨宇彤发布了新的文献求助10
30秒前
30秒前
大桃完成签到,获得积分10
32秒前
冷静乌发布了新的文献求助10
33秒前
脆香可丽饼完成签到,获得积分10
34秒前
35秒前
35秒前
豪豪完成签到,获得积分10
37秒前
37秒前
38秒前
40秒前
哭泣老三发布了新的文献求助10
40秒前
40秒前
GE葛完成签到 ,获得积分10
42秒前
怕黑愫发布了新的文献求助10
42秒前
高分求助中
Becoming: An Introduction to Jung's Concept of Individuation 600
Ore genesis in the Zambian Copperbelt with particular reference to the northern sector of the Chambishi basin 500
A new species of Coccus (Homoptera: Coccoidea) from Malawi 500
A new species of Velataspis (Hemiptera Coccoidea Diaspididae) from tea in Assam 500
PraxisRatgeber: Mantiden: Faszinierende Lauerjäger 500
Mantiden: Faszinierende Lauerjäger Faszinierende Lauerjäger 400
Blattodea, Mantodea, Isoptera, Grylloblattodea, Phasmatodea, Dermaptera and Embioptera, Volume 3, Part 2 400
热门求助领域 (近24小时)
化学 医学 生物 材料科学 工程类 有机化学 生物化学 物理 内科学 纳米技术 计算机科学 化学工程 复合材料 基因 遗传学 催化作用 物理化学 免疫学 量子力学 细胞生物学
热门帖子
关注 科研通微信公众号,转发送积分 3165538
求助须知:如何正确求助?哪些是违规求助? 2816691
关于积分的说明 7913299
捐赠科研通 2476143
什么是DOI,文献DOI怎么找? 1318707
科研通“疑难数据库(出版商)”最低求助积分说明 632179
版权声明 602388