TY - JOUR
T1 - A Semidecentralized PKI System Based on Public Blockchains with Automatic Indemnification Mechanism
AU - Hwang, Gwan Hwan
AU - Chang, Tao Ku
AU - Chiang, Hung Wen
N1 - Publisher Copyright:
© 2021 Gwan-Hwan Hwang et al.
PY - 2021
Y1 - 2021
N2 - The PKI framework is a widely used network identity verification framework. Users will register their identity information with a certification authority to obtain a digital certificate and then show the digital certificate to others as an identity certificate. After others receive the certificate, they must check the revocation list from the CA to confirm whether the certificate is valid. Although this architecture has a long history of use on the Internet, significant doubt surrounds its security. Because the CA may be attacked by DDoS, the verifier may not obtain the revocation list to complete the verification process. At present, there are many new PKI architectures that can improve on the CA's single point of failure, but since they still have some shortcomings, the original architecture is still used. In this paper, we proposed a semidecentralized PKI architecture that can easily prevent a single point of failure. Users can obtain cryptographic evidence through specific protocols to clarify the responsibility for the incorrect certificate and then submit the cryptographic evidence to the smart contract for automatic judgment and indemnification.
AB - The PKI framework is a widely used network identity verification framework. Users will register their identity information with a certification authority to obtain a digital certificate and then show the digital certificate to others as an identity certificate. After others receive the certificate, they must check the revocation list from the CA to confirm whether the certificate is valid. Although this architecture has a long history of use on the Internet, significant doubt surrounds its security. Because the CA may be attacked by DDoS, the verifier may not obtain the revocation list to complete the verification process. At present, there are many new PKI architectures that can improve on the CA's single point of failure, but since they still have some shortcomings, the original architecture is still used. In this paper, we proposed a semidecentralized PKI architecture that can easily prevent a single point of failure. Users can obtain cryptographic evidence through specific protocols to clarify the responsibility for the incorrect certificate and then submit the cryptographic evidence to the smart contract for automatic judgment and indemnification.
UR - http://www.scopus.com/inward/record.url?scp=85118994720&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=85118994720&partnerID=8YFLogxK
U2 - 10.1155/2021/7400466
DO - 10.1155/2021/7400466
M3 - Article
AN - SCOPUS:85118994720
SN - 1939-0114
VL - 2021
JO - Security and Communication Networks
JF - Security and Communication Networks
M1 - 7400466
ER -