BRT: An Efficient and Scalable Blockchain-Based Revocation Transparency System for TLS Connections

被引:0
作者
Xing, Qianqian [1 ]
Wang, Xiaofeng [1 ]
Xu, Xinyue [1 ]
Lin, Jiaqi [2 ]
Wang, Fei [1 ]
Li, Cui [1 ]
Wang, Baosheng [1 ]
机构
[1] Natl Univ Def Technol, Coll Comp, Changsha 410073, Peoples R China
[2] Inst Syst Engn AMS PLA, Beijing 100039, Peoples R China
基金
中国国家自然科学基金; 国家重点研发计划;
关键词
PKI and TLS security; revocation; blockchain;
D O I
10.3390/s23218816
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
Log-based public key infrastructure(PKI) refers to a robust class of CA-attack-resilient PKI that enhance transparency and accountability in the certificate revocation and issuance process by compelling certificate authorities (CAs) to submit revocations to publicly and verifiably accessible logs. However, log-based PKIs suffer from a reliance on centralized and consistent sources of information, rendering them susceptible to split-world attacks, and they regrettably fail to provide adequate incentives for recording or monitoring CA behavior. Blockchain-based PKIs address these limitations by enabling decentralized log audits through automated financial incentives. However, they continue to face challenges in developing a scalable revocation mechanism suited for lightweight clients. In this paper, we introduce BRT, a scalable blockchain-based system for certificate and revocation transparency. It serves to log, audit, and validate the status of certificates within the transport layer security (TLS)/secure sockets layer(SSL) PKI domain. We designed an audit-on-chain framework, coupled with an off-chain storage/computation system, to enhance the efficiency of BRT when operating in a blockchain environment. By implementing a blockchain-based prototype, we demonstrate that BRT achieves storage-efficient log recording with a peak compression rate reaching 8%, cost-effective log updates for large-scale certificates, and near-instantaneous revocation checks for users.
引用
收藏
页数:23
相关论文
共 63 条
  • [1] A blockchain-based certificate revocation management and status verification system
    Adja, Yves Christian Elloh
    Hammi, Badis
    Serhrouchni, Ahmed
    Zeadally, Sherali
    [J]. COMPUTERS & SECURITY, 2021, 104
  • [2] [Anonymous], 2020, Provable Documentation
  • [3] [Anonymous], 2023, Band Protocol-Cross-Chain Data Oracle
  • [4] [Anonymous], 2015, PROC INT C NETW SYS
  • [5] [Anonymous], 2023, Plasma Chains|ethereum.org
  • [6] [Anonymous], 2023, Arbitrum-The Future of Ethereum
  • [7] [Anonymous], 2023, Proof-of-Work (PoW)|ethereum.org
  • [8] [Anonymous], 2023, Proof-of-Stake (PoS)|ethereum.org
  • [9] [Anonymous], 2015, Incidents Involving the CA WoSign
  • [10] [Anonymous], 2023, An Open System to Manage Data without a Central Server|IPFS