The quest of privacy in public key infrastructure
Leila Benarous, Benamar Kadri · International Journal of Blockchains and Cryptocurrencies · 2021
The public key infrastructure (PKI) is the backbone of internet security. It ensures the authenticity, integrity, and non-repudiation. The certified public keys are life-timed. They may be revoked upon personal change, private key exposure or misbehaviour occurrence. Their use is secure and traceable. Yet, this traceability trait and the identity-based certificate usage may violate the user's privacy. Therefore, there needs to be a balance between the accountability and authenticity requirements on the one hand and the privacy demand on the other hand. In this paper, we design a blockchain-based privacy-aware public key infrastructure system, which guarantees the same security properties besides ensuring the privacy. The users have two types of elliptic curve cryptography (ECC) keys, identity-based long-term certified keys and on-the-fly temporal anonymous keys denoted as pseudonyms. These pseudonyms are stored and published on the blockchain. The proposed PKI achieves a similar security level as that of the conventional PKI while ensuring the privacy.