A Mediated RSA-Based End Entity Certificates Revocation Mechanism in Grid

Jinpei Pan, Mingchu Li, Weifeng Sun, Jing Hu · 2009

The end entity certificates (EECs) revocation mechanism in grid security infrastructure (GSI) adopts certificate revocation list (CRL) currently. However, CRL is an inefficient mechanism with drawbacks of "time granularity problem" and unmanageable sizes. This paper presents a new EECs revocation mechanism MEECRM (mediated RSA-based end entity certificates revocation mechanism) combined with MyProxy - the online credential repository in Globus Tookit (GT). MEECRM can ensure instantaneous revocation of invalid EECs in grid environments and can be used in many large-scale grid projects because of inheriting from MyProxy. Analyses also prove that MEECRM is secure.

Read the paper · More papers on PaperTik