Prototype of the Accountable Key Infrastructure
Lorenzo Baesso · Repository for Publications and Research Data (ETH Zurich) · 2014
Current Public Key Infrastructures (PKIs) rely on a very high level of trust in Certificate Authorities (CAs). Sometimes this can be dangerous as CAs can be compromised. The Accountable Key Infrastructure (AKI) aims at distributing trust among multiple parties in order to avoid single points of failure and at the same time give the possibility to domain owners to decide whom they shall trust. Moreover this infrastructure is able to handle common operations, like certificates registration and revocation, as well as detection of misuse cases (e.g. CAs or domain private keys get compromised). My contribution consists in designing, implementing, and testing a prototype of AKI. In this paper I first introduce the parties involved and the certificates used in this architecture. I explain what these new certificates are used for and how to create them. Then the core part of my work is discussed: the actual infrastructure on which AKI runs. Meaning which requirements need to be considered, which are the possible workflows, and how the parties are actually implemented. I also give an elucidation on the possible use cases; that is, all possible functionalities domains are provided by this first implementation of AKI. Finally I show the results from my tests and I make my considerations. The first part of the analysis focuses on how the time is fractioned for cryptographic operations, computational operations, etc. Then I examine the system’s performance. That is, I show the results of some stress-tests in which the aim is to find the number of processed requested per second. I also make a study of the introduced bandwidth overhead analyzing the size of the exchanged messages, for all use cases. The last part of the analysis is an informal security analysis in which I discuss the system’s resiliency to well known attacks (e.g. Denial of Service attack, replay attack, etc.) and I suggest which improvements could be done in the future.