The Research and Design of the Proxy for Certificate Validation Based on Distributed Cross-Certification
Yan Liu, Zhe Yang
Abstract
Yan Liu, Zhe Yang
Abstract
This paper chooses a typical model (PKI hybrid trust model) as the paper's research sample which has more applicability and practicability. This paper proposes a scheme of constructing a trusted proxy for certificate validation and gives out a proxy's framework model. By transferring the work of certification path building and validation to the proxy, this scheme solves the "fat" PKI client problem. The paper designs the message data structures in SCVP request and response, and let PKI clients using these messages to interact with the proxy. The paper also gives out the details of the path-building module. It proposes an algorithm to build the certification paths to the PKI trust model chosen by this paper. The paper illustrates the detailed processing in path building. Besides the paper proposes a scheme that optimizes the path building algorithm by completing some work of path validation during the process of path building. The optimized scheme could eliminate some invalid intermediate certificates, and give intermediate certificates the weight which is used to sort, so that the paths built can be more possibly valid and the proxy can be more efficient.
OpenAlex reports 6 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
This paper chooses a typical model (PKI hybrid trust model) as the paper's research sample which has more applicability and practicability. This paper proposes a scheme of constructing a trusted proxy for certificate validation and gives out a proxy's framework model. By transferring the work of certification path building and validation to the proxy, this scheme solves the "fat" PKI client problem. The paper designs the message data structures in SCVP request and response, and let PKI clients using these messages to interact with the proxy. The paper also gives out the details of the path-building module. It proposes an algorithm to build the certification paths to the PKI trust model chosen by this paper. The paper illustrates the detailed processing in path building. Besides the paper proposes a scheme that optimizes the path building algorithm by completing some work of path validation during the process of path building. The optimized scheme could eliminate some invalid intermediate certificates, and give intermediate certificates the weight which is used to sort, so that the paths built can be more possibly valid and the proxy can be more efficient.
Key concepts: Proxy (statistics), Computer science, Certificate, Public key infrastructure, Certification, Path (computing), Scheme (mathematics), Trust anchor