Improving the Scalability of PrivacyCAs
Yanzhou Zhou, Chaoling Li, LI Li-xin, Li Wenjun · 2009
The PrivacyCA defined in Trusted Computing Group (TCG) specifications may be the performance bottleneck of trusted applications, because it needs to be involved in every transaction of attestation to maximize privacy and in a future trust-enabled Internet a PrivacyCA potentially has to serve millions of customers. In this paper we show how the scalability of PrivacyCA can be improved. In this context, we propose two models of PrivacyCA individually based on agents and virtualization technologies. In the agents-based model, the PrivacyCA authorizes a series of agents to issue AIK certificates and only issues a few VK certificates itself. The virtualization-based model provides large number of PrivacyCA instances running on virtual machines to deal with AIK requests. Both models not only improve the scalability of PrivacyCA, but also enhance its security and privacy preserving ability.