2012
DOI: 10.1002/spe.2148
|View full text |Cite
|
Sign up to set email alerts
|

FcgiOCSP: a scalable OCSP‐based certificate validation system exploiting the FastCGI interface

Abstract: SUMMARYCertificate validation, one of the most important and complex tasks in Public Key Infrastructures, is still a challenging topic nowadays because of the scalability and complexity issues related to this process. Validation of an X.509 certificate requires checking its revocation status, either by consulting the so‐called Certificate Revocation Lists or by contacting a specific server via the Online Certificate Status Protocol (OCSP). Because more and more entities extensively need to validate the certifi… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
2

Citation Types

0
6
0

Year Published

2018
2018
2024
2024

Publication Types

Select...
2
2
1

Relationship

0
5

Authors

Journals

citations
Cited by 5 publications
(6 citation statements)
references
References 16 publications
(19 reference statements)
0
6
0
Order By: Relevance
“…Therefore, according to the works of [9,10,[12][13][14][15], we improve the certificate verification scheme based on OCSP. In this paper, our contributions are as follows:…”
Section: Our Contributionmentioning
confidence: 99%
See 4 more Smart Citations
“…Therefore, according to the works of [9,10,[12][13][14][15], we improve the certificate verification scheme based on OCSP. In this paper, our contributions are as follows:…”
Section: Our Contributionmentioning
confidence: 99%
“…(1) Based on the related works [10,[13][14][15], we improve the interaction process between the communication entity and the network in the whole certificate verification: (a) we optimize the number of connections between the wireless communication entity and the wired network, and during the certificate verification process, the content server sends the OCSP query request directly so as to reduce the time and the consumption of wireless network bandwidth, compared with that the mobile terminal sends the query request; (b) we reduce the time and the consumption of network bandwidth when wireless communication entity needs to download the certificate; compared with the works [10,[13][14][15], the wireless communication entity does not need to download the CA certificate and the ARL in our the proposed scheme; thus the verification process of the CA certificate is committed to the OCSP server; although the directory server needs to send the mobile terminal certificate to the content server, the procedure is finished in the wired network, and thus the cost is beneficial; (c) if the OCSP server requires the signed OCSP query request, then in the original scheme the mobile terminal needs to send its own certificate to the OCSP server to be verified through the wireless network, and thus the occupied time and consumption of network bandwidth, however increase; in our proposed scheme, the content server sends its own certificate to the OCSP server through the wired network, such communication efficiency is much higher, and because the number of content servers is much smaller than the number of mobile terminals, the amount of data sent by the entire authentication process is reduced.…”
Section: Our Contributionmentioning
confidence: 99%
See 3 more Smart Citations