A framework toward a self-organizing and self-healing certificate authority group in a Content Addressable Network

Anuchart Tassan, Guang Gong · 2010

Public-key provision in on Internet scale is crucial for securing peer-to-peer (P2P) applications. This paper proposes a framework for a self-organizing and self-healing certificate authority (CA) in a Content Addressable Network (CAN) that can provide certificates without a centralized Trusted Third Party (TTP). In our framework, a CA group is initialized by bootstrapping nodes and then grows to a mature state by itself. Based on our group management policies, the membership in the CA group is dynamic and has a uniform distribution over the P2P community. Meanwhile, the honest majority of the CA group is maintained by a Byzantine agreement algorithm, and all shares of the CA group are refreshed gradually and continuously. A security analysis shows that the framework enables key registration and certificate issue with resistance to man-in-the-middle (MITM), collusion, and node impersonation attacks.

Read the paper · More papers on PaperTik