OPTIMAL CERTIFICATE UPDATE INTERVAL CONSIDERING COMMUNICATION COSTS IN PKI
Shigenari Nakamura, Miwako Arafuka, T. NAKAGAWA · WORLD SCIENTIFIC eBooks · 2007
AbstractCA (Certification Authority) in PKI (Public Key Infrastructure) issues the certification pubic keys to the user as the method of proving the owner of the public keys. When various circumstances may cause that a certificate becomes invalid prior to the expiration of the validity period, the PKI user confirms the certificate is effective in regularly acquiring CRL(Certification Revocation List) from the repository. For this, there is an inquiry method by online. However, supplying real-time information on revocation status during each of acquiring is computationally expensive. In addition, the transmission of large CRLs to potentially many clients can be prohibitively expensive. Then, we analytically discuss optimal issuing cycle times of CRL which minimize the various expected costs per unit of time.