A framework for intrusion tolerant certification authority system evaluation

被引:1
作者
Lin, Jingqiang [1 ]
Jing, Jiwu [2 ]
Liu, Peng [3 ]
机构
[1] Chinese Acad Sci, Grad Sch, State Key Lab Informat Secur, Beijing 100049, Peoples R China
[2] State Key Lab Informat Secur, Grad Sch CAS, Beijing 100049, Peoples R China
[3] Penn State Univ, University Pk, PA 16802 USA
来源
SRDS 2007: 26TH IEEE INTERNATIONAL SYMPOSIUM ON RELIABLE DISTRIBUTED SYSTEMS, PROCEEDINGS | 2007年
关键词
D O I
10.1109/SRDS.2007.14
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Various. intrusion tolerant certification authority (CA) systems have been recently proposed to provide attack resistant certificate update/query services. However, it is difficult to compare them against each other directly due to diversity in system organizations, threshold cryptography schemes, protocols and usage scenarios. We present a framework for intrusion tolerant CA system evaluation, which consists of three components, namely, an intrusion tolerant C,4 model, a threat model and a metric for comparative evaluation. The framework covers system organizations, protocols, usage scenarios, period of certificate validity, revocation rate and mean time to recovery (MTTR). Based on the framework, four representative CA systems. are evaluated and compared in three typical usage scenarios, producing reasonable and insightful results. The inter-dependency between usage scenarios and system characteristics is investigated, providing a guideline to design better systems for different usage scenarios. The proposed framework provides an effective method to evaluate intrusion tolerant C,4 systems quantitatively. Moreover, the comparison results offer valuable insights to further improve the attack resilience of intrusion tolerant CA systems.
引用
收藏
页码:231 / +
页数:3
相关论文
共 27 条
  • [1] *CERT CC, 1988, STAT
  • [2] *CSI FBI, 2005, COMP CRIM SEC SURV
  • [3] DESMEDT Y, 1992, LECT NOTES COMPUT SC, V576, P457
  • [4] Gemmell PS, 1997, CRIPTOBYTES TECHNICA, V2, P7
  • [5] Goseva-Popstojanova K, 2001, DISCEX'01: DARPA INFORMATION SURVIVABILITY CONFERENCE & EXPOSITION II, VOL II, PROCEEDINGS, P211, DOI 10.1109/DISCEX.2001.932173
  • [6] GRAY R, 2004, ACM IEEE MSWIM, P220
  • [7] GUPTA V, 2003, LADC, P81
  • [8] *ISO IEC, COMM CRIT INF TECHN
  • [9] Jing J, 2003, 1 ACM WORKSH SURV SE, P53
  • [10] KLAYANAKRISHNAN M, 1997, IEEE ICCCN, P418