A distributed online certificate status protocol for named data networks
Daniel Rezende, Carlos Maziero, Elisa Mannes · 2018
The Named Data Network (NDN) is a research activity towards the Internet of the Future, aiming to provide named content regardless location, application, or transport protocol. To secure content distribution, NDN uses a security model in which contents are digitally signed by their producers. Consumers must retrieve public keys to validate a content's signature, and need to check the validity status of those keys before using them. Traditional public key infrastructures use Certificate Revocation Lists (CRL) and the Online Certificate Status Protocol (OCSP) to disseminate key status information. However, such systems must be adapted to work on the NDN architecture. This paper proposes a replication system approach to disseminate key status information in NDN, regardless the key management system adopted. Replication techniques improve robustness, reduce convergence time, and improve key status availability throughout the network. Main results show a significant reduction in response time for consulting a key status, when compared to retrieving it from the original data producer.