PKI without Revocation Checking

Karl Scheibelhofer · 2005

Current X.509-based PKIs are typically complex. One of the most critical parts is revocation checking. Providing revocation information is a big effort for CAs, and for clients it is even more costly to get all re-quired revocation data. This work provides a performance calculation of two CA setups with CRLs, delta CRLs and OCSP as revo-cation checking mechanism. The enhance-ment of this work is the proposal to avoid revocation checking by issuing certificates on-line and only retroactively. An analysis shows that this approach performs at least as good as OCSP and much better than CRLs. In addition, this solution reduces the complexity of PKI significantly.

Read the paper · More papers on PaperTik