Evaluation of certificate revocation policies: OCSP vs. Overissued-CRL
José L. Muñoz, Jordi Forné, Jesús Castro González
Abstract
José L. Muñoz, Jordi Forné, Jesús Castro González
Abstract
Public key cryptography is widely used to provide Internet security services. PKI is the infrastructure that supports public key cryptography and revocation of certificates implies one of its major costs. In this paper we propose a model to compare revocation policies and use it to compare the main revocation policies: OCSP and Overissued-CRL.
OpenAlex reports 21 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Public key cryptography is widely used to provide Internet security services. PKI is the infrastructure that supports public key cryptography and revocation of certificates implies one of its major costs. In this paper we propose a model to compare revocation policies and use it to compare the main revocation policies: OCSP and Overissued-CRL.
Key concepts: Revocation list, Revocation, Public key infrastructure, Computer security, Public-key cryptography, Computer science, Implicit certificate, Root certificate