A mediated RSA-based end entity certificates revocation mechanism with secure concerned in grid

Weifeng Sun, Juanyun Wang, Boxiang Dong, Mingchu Li, Zhenquan Qin

Research output: Contribution to journalArticle

5 Scopus citations

Abstract

The End Entity Certificates (EECs) revocation mechanism in Grid Security Infrastructure (GSI) adopts Certificate Revocation List (CRL) currently. However, CRL is an inefficient mechanism with drawbacks of "time granularity problem" and unmanageable sizes. This paper presents a new EECs revocation mechanism MEECRM (Mediated RSA-based End Entity Certificates Revocation Mechanism) to eliminate "key escrow" problem. MEECRM combines with MyProxy - the online credential repository in Globus Tookit (GT). And some Schemes, such as HMAC, multi-SEM support and PVSS, have been introduced into MEECRM to increase the security and efficiency. MEECRM can ensure instantaneous revocation of invalid EECs in grid environments and can be used in many large-scale grid projects because of inheriting from MyProxy. Analyses also prove that MEECRM is secure.

Original languageEnglish
Pages (from-to)103-114
Number of pages12
JournalInternational Journal of Information Processing and Management
Volume1
Issue number2
DOIs
StatePublished - 1 Dec 2010

Keywords

  • Certificate revocation
  • Key escrow
  • Mediated RSA
  • Security mediator

Fingerprint Dive into the research topics of 'A mediated RSA-based end entity certificates revocation mechanism with secure concerned in grid'. Together they form a unique fingerprint.

  • Cite this