Let’s Re-Sign! Analysis and Equivocation-Resistant Distribution of OpenPGP Revocations

Tobias Mueller · 2022 International Conference on Information Networking (ICOIN) · 2022

Certificates are commonly used for enabling secure communication. Private, secure and efficient dissemination of their revocation is essential to maintain security properties such as confidentiality. However, managing revocations remains a challenge not only on the Web but also for protocols building on OpenPGP, such as Email. Currently, no dedicated protocol for managing revocations exists. Instead, clients upload or fetch full certificates, which may include a revocation signature. This paper presents a dedicated protocol for disseminating revocations which improves the security over the status quo by providing incentives to the server to behave benignly. The protocol builds on the Certificate Transparency log of the Web to store and retrieve OpenPGP revocations. It thus inherits the property of being resilient against equivocation attacks. Compared to the status quo, the dedicated protocol does not serve the full certificate containing personally identifiable information thus improving privacy. This paper also shows how serving the revocation signature separately from the full certificate improves efficiency.

Read the paper · More papers on PaperTik