BlockPGP: A Blockchain-based Framework for PGP Key Servers

被引:12
作者
Yakubov, Alexander [1 ]
Shbair, Wazen M. [1 ]
State, Radu [1 ]
机构
[1] Univ Luxembourg, SnT, 29 Ave JF Kennedy, L-1855 Luxembourg, Luxembourg
来源
2018 SIXTH INTERNATIONAL SYMPOSIUM ON COMPUTING AND NETWORKING WORKSHOPS (CANDARW 2018) | 2018年
关键词
PGP; Pretty Good Privacy; Blockchain; Ethereum; Key server; PKI; Public key infrastructure;
D O I
10.1109/CANDARW.2018.00065
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Pretty Good Privacy (PGP) is one of the most prominent cryptographic standards offering end-to-end encryption for email messages and other sensitive information. PGP allows to verify the identity of the correspondent in information exchange as well as the information integrity. PGP implements asymmetric encryption with certificates shared through a network of PGP key servers. Many recent breaches show that certificate infrastructure can be compromised as well as exposed to operational errors. In this paper we propose a new PGP management framework with the key server infrastructure implemented using blockchain technology. Our framework resolves some problems of PGP key servers focusing in particular on fast propagation of certificate revocation among key servers and elimination of man-in-the-middle risk. We also provided user access right control where only the certificate holder can change information related to the certificate. We designed and developed a prototype for key server deployment on permissioned Ethereum blockchain. Permissioned blockchain should allow to control the costs of PGP key server infrastructure maintenance at the present level.
引用
收藏
页码:316 / 322
页数:7
相关论文
共 22 条
[1]  
Ali M, 2016, PROCEEDINGS OF USENIX ATC '16: 2016 USENIX ANNUAL TECHNICAL CONFERENCE, P181
[2]  
Anada H., 2014, INT C TRUST SYST, P1
[3]  
Androulaki E., 2017, ERCIM NEWS, V2017
[4]  
[Anonymous], 2013, TECH REP
[5]  
[Anonymous], 2016, IACR Cryptol. ePrint Arch.
[6]  
[Anonymous], 2003, Understanding PKI: concepts, standards, and deployment considerations
[7]  
[Anonymous], 2014, TYPES SSL CERTIFICAT
[8]  
[Anonymous], 2014, TECH REP
[9]  
[Anonymous], 1999, GNU OPENPGP PRIVACY
[10]  
[Anonymous], 2017, PROC 14 INT C SECURI