发明授权
- 专利标题: Method and apparatus for providing efficient management of certificate revocation
- 专利标题(中): 提供有效管理证书撤销的方法和装置
-
申请号: US13882812申请日: 2010-11-05
-
公开(公告)号: US09083535B2公开(公告)日: 2015-07-14
- 发明人: Atefeh Mashatan , Imad Aad , Rafik Chaabouni , Pentti Valtteri Niemi , Serge Vaudenay
- 申请人: Atefeh Mashatan , Imad Aad , Rafik Chaabouni , Pentti Valtteri Niemi , Serge Vaudenay
- 申请人地址: FI Espoo
- 专利权人: Nokia Corporation
- 当前专利权人: Nokia Corporation
- 当前专利权人地址: FI Espoo
- 代理机构: Mintz Levin Cohn Ferris Glovsky and Popeo, P.C.
- 国际申请: PCT/IB2010/055047 WO 20101105
- 国际公布: WO2012/059794 WO 20120510
- 主分类号: H04L9/32
- IPC分类号: H04L9/32 ; H04L29/06
摘要:
A method for providing efficient management of certificate revocation may comprise storing a list of identifiers of digital certificates including a revocation list defining a list of revoked certificates in an accumulator, storing a witness value in association with at least some entries in the revocation list in which the witness value provides proof of the membership or non-membership of an identifier in the revocation list, enabling generation of a new accumulator and a new witness value responsive to each insertion or deletion of an entry in the revocation list, and enabling batch updates to the revocation list using a reduced bitlength value generated based on to a ratio of a value generated based on elements added to the revocation list to a value generated based on elements deleted from the revocation list. A corresponding apparatus is also provided. A method for certificate authorities (CA) that use Bloom filters for certificate revocation list (CRL) compression that enables the CA to hash only the entry that is to be un-revoked so that a good compression rate may be provided while avoiding computation of the entire CRL for each un-revocation.
公开/授权文献
信息查询