Public key X. 509 certificates play a powerful role in promoting effective electronic identification, but some significant practical issues still affect their scalability. Every time a public key certificate is used, it must be validated by the system or application relying on it for security services, generically called also relying party. The validation involves several processing steps and checks, and it has been measured that many applications (still) perform it incompletely. Furthermore, privacy issues may occur when validating certificates, for example a website visited by a user could be revealed to external parties. We propose TPValCert, an architecture tailoring a trusted proxy to provide privacy-preserving certificate validation service to the relying parties. By exploiting TPValCert, a desktop, IoT, or mobile system that needs to validate a public-key certificate may execute a transaction with a trusted proxy, which performs validation by considering certificate policy parameters, privacy, and validation options received from the client and returns the validation status. Besides reducing complexity on the client, exploiting such trusted validation parties may also bring privacy benefits. To communicate with the clients, we consider the SCVP (Server-based Certificate Validation Protocol) or DVCS (Data Validation and Certification Server) protocols, even though, depending on the context, lighter formats could be considered. Our implementation efforts emphasize the possibility of pursuing a tradeoff between timeliness, privacy, and computational resource usage, via dynamic selection of several configurable options.
TPValCert: Privacy-Preserving Trusted Proxy for Public Key Certificate Validation / Berbecaru, Diana. - ELETTRONICO. - (2025). ( 2025 IEEE Symposium on Computers and Communications (ISCC) Bologna (ITA) 2-5 July 2025) [10.1109/ISCC65549.2025.11326465].
TPValCert: Privacy-Preserving Trusted Proxy for Public Key Certificate Validation
Berbecaru, Diana
2025
Abstract
Public key X. 509 certificates play a powerful role in promoting effective electronic identification, but some significant practical issues still affect their scalability. Every time a public key certificate is used, it must be validated by the system or application relying on it for security services, generically called also relying party. The validation involves several processing steps and checks, and it has been measured that many applications (still) perform it incompletely. Furthermore, privacy issues may occur when validating certificates, for example a website visited by a user could be revealed to external parties. We propose TPValCert, an architecture tailoring a trusted proxy to provide privacy-preserving certificate validation service to the relying parties. By exploiting TPValCert, a desktop, IoT, or mobile system that needs to validate a public-key certificate may execute a transaction with a trusted proxy, which performs validation by considering certificate policy parameters, privacy, and validation options received from the client and returns the validation status. Besides reducing complexity on the client, exploiting such trusted validation parties may also bring privacy benefits. To communicate with the clients, we consider the SCVP (Server-based Certificate Validation Protocol) or DVCS (Data Validation and Certification Server) protocols, even though, depending on the context, lighter formats could be considered. Our implementation efforts emphasize the possibility of pursuing a tradeoff between timeliness, privacy, and computational resource usage, via dynamic selection of several configurable options.| File | Dimensione | Formato | |
|---|---|---|---|
|
1571119168 final.pdf
accesso aperto
Tipologia:
2. Post-print / Author's Accepted Manuscript
Licenza:
Pubblico - Tutti i diritti riservati
Dimensione
434 kB
Formato
Adobe PDF
|
434 kB | Adobe PDF | Visualizza/Apri |
|
TPValCert_Privacy-Preserving_Trusted_Proxy_for_Public_Key_Certificate_Validation.pdf
accesso riservato
Tipologia:
2a Post-print versione editoriale / Version of Record
Licenza:
Non Pubblico - Accesso privato/ristretto
Dimensione
461.58 kB
Formato
Adobe PDF
|
461.58 kB | Adobe PDF | Visualizza/Apri Richiedi una copia |
Pubblicazioni consigliate
I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.
https://hdl.handle.net/11583/3002916
