Hardening X.509 Certificate Issuance using Distributed Ledger Technology

被引:0
作者
Kinkelin, Holger [1 ]
von Seck, Richard [1 ]
Rudolf, Christoph [1 ]
Carle, Georg [1 ]
机构
[1] Tech Univ Munich, Dept Informat, Chair Network Architectures & Serv, D-85748 Garching, Germany
来源
NOMS 2020 - PROCEEDINGS OF THE 2020 IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM 2020: MANAGEMENT IN THE AGE OF SOFTWARIZATION AND ARTIFICIAL INTELLIGENCE | 2020年
关键词
Identity management; X.509; distributed ledger; policy-based security;
D O I
10.1109/noms47738.2020.9110311
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The security of cryptographic communication protocols that use X.509 certificates depends on the correctness of those certificates. This paper proposes a system that helps to ensure the correct operation of an X.509 certification authority and its registration authorities. We achieve this goal by enforcing a policy-defined, multi-party validation and authorization workflow of certificate signing requests. Besides, our system offers full accountability for this workflow for forensic purposes. As a foundation for our implementation, we leverage the distributed ledger and smart contract framework Hyperledger Fabric. Our implementation inherits the strong tamper-resistance of Fabric which strengthens the integrity of the computer processes that enforce the validation and authorization of the certificate signing request, and of the metadata collected during certificate issuance.
引用
收藏
页数:6
相关论文
empty
未找到相关数据