Efficient Approaches to Ensure Certificate Authenticity for Public Key Infrastructure
John Barclay, Vijay Kansara, Eknath Eswar, Khaled M. Elleithy, Laiali H. Almazaydeh · Information Technology Journal · 2017
Background and Objective: The public key infrastructure provides secure digital certificates required to establish secure transactions over the networks.The certificates are intended to act as the sole item needed to authenticate an entity.However, fraudulent certificates become one of the challenges faced by the public key infrastructure, which have impacted the usersʼ trust in certificates.A user must validate the certificate with the issuing certificate authority.Checking every certificate with the certificate authority is costly in time and bandwidth.It also eliminates one of the benefits of certificates, which is offline authentication.In this study, different methods were explored for deciding when to contact the certificate authority for authorization with a focus on minimizing the risk of accepting a fraudulent certificate while maintaining the benefit of offline authentication.Materials and Methods: This study analyzed Certificate Revocation List (CRL) and Online Certificate Status Protocol (OCSP) requests.Most of the related approaches can roughly provide potential options for increasing the scalability of the Public Key Infrastructure (PKI).Nevertheless, only few recent approaches addressed a tradeoff risk versus cost.As it is well known, at the point when reducing oneʼs risk, it is almost that cost is increased.Results: Simulation results showed the relationship between risk and changes in criteria through generated graph from the experiment.With that hybrid technique for checking the revocation status of a certificate, this research ponders on a relationship between risk and cost that is non-linear.Based on experiment results, policies could be created that provide the best risk to cost ratio for specific environments.Conclusion: From results it is concluded that checking certificates based on the age of a cached certificate revocation lists provided the best relationship between cost and security.Combining it with other features will either reduce the potential cost to security ratio or reduce the flexibility of the method.