The Experts below are selected from a list of 1569 Experts worldwide ranked by ideXlab platform

Warwick Ford - One of the best experts on this subject based on the ideXlab platform.

  • The Machine-to-Machine (M2M) Public Key Certificate Format
    2015
    Co-Authors: Yuri Poeluev, Warwick Ford
    Abstract:

    The X.509 public key Certificate Format is overly verbose for Internet-of-Things (IoT) constrained environments, where nodes with limited memory and networks with limited bandwidth are not uncommon. The Machine-to-Machine (M2M) Certificate Format is a pruned down and encoding-optimized replacement for X.509, which reuses much of the X.509 semantics but reduces Certificate sizes by typically 40%. We are proposing that IETF recognize the M2M Format as an optional replacement for X.509 in Internet applications including, but not limited to, TLS and DTLS.

  • internet x 509 public key infrastructure Certificate and Certificate revocation list crl profile
    RFC, 2002
    Co-Authors: Russ Housley, W Polk, Warwick Ford, D Solo
    Abstract:

    This memo profiles the X.509 v3 Certificate and X.509 v2 Certificate Revocation List (CRL) for use in the Internet. An overview of this approach and model are provided as an introduction. The X.509 v3 Certificate Format is described in detail, with additional inFormation regarding the Format and semantics of Internet name forms. Standard Certificate extensions are described and two Internet-specific extensions are defined. A set of required Certificate extensions is specified. The X.509 v2 CRL Format is described in detail, and required extensions are defined. An algorithm for X.509 certification path validation is described. An ASN.1 module and examples are provided in the appendices.

  • internet x 509 public key infrastructure Certificate and crl profile
    RFC, 1999
    Co-Authors: Russ Housley, W Polk, Warwick Ford, D Solo
    Abstract:

    This memo profiles the X.509 v3 Certificate and X.509 v2 CRL for use in the Internet. An overview of the approach and model are provided as an introduction. The X.509 v3 Certificate Format is described in detail, with additional inFormation regarding the Format and semantics of Internet name forms (e.g., IP addresses). Standard Certificate extensions are described and one new Internet-specific extension is defined. A required set of Certificate extensions is specified. The X.509 v2 CRL Format is described and a required extension set is defined as well. An algorithm for X.509 Certificate path validation is described. Supplemental inFormation is provided describing the Format of public keys and digital signatures in X.509 Certificates for common Internet public key encryption algorithms (i.e., RSA, DSA, and Diffie-Hellman). ASN.1 modules and examples are provided in the appendices.

  • Certificate and CRL Profile
    1999
    Co-Authors: D Solo, Russ Housley, Warwick Ford
    Abstract:

    When complete, this specification will obsolete RFC 2459. Please send comments on this document to the ietf-pkix@imc.org mail list. This memo profiles the X.509 v3 Certificate and X.509 v2 CRL for use in the Internet. An overview of the approach and model are provided as an introduction. The X.509 v3 Certificate Format is described in detail, with additional inFormation regarding the Format and semantics of Internet name forms (e.g., IP addresses). Standard Certificate extensions are described and one new Internet-specific extension is defined. A required set of Certificate extensions is specified. The X.509 v2 CRL Format is described and a required extension set is defined as well. An algorithm for X.509 Certificate path validation is described. Supplemental inFormation is provided describing the Format of public keys and digital signatures in X.509 Certificates for common Internet public key encryption algorithms (i.e., RSA, DSA, and Diffie- Hellman). ASN.1 modules and examples are provided in the appendices.

Giuseppe Ateniese - One of the best experts on this subject based on the ideXlab platform.

  • NSS - From Pretty Good to Great: Enhancing PGP Using Bitcoin and the Blockchain
    Network and System Security, 2015
    Co-Authors: Duane Wilson, Giuseppe Ateniese
    Abstract:

    PGP is built upon a Distributed Web of Trust in which a user’s trustworthiness is established by others who can vouch through a digital signature for that user’s identity. Preventing its wholesale adoption are a number of inherent weaknesses to include (but not limited to) the following: 1) Trust Relationships are built on a subjective honor system, 2) Only first degree relationships can be fully trusted, 3) Levels of trust are difficult to quantify with actual values, and 4) Issues with the Web of Trust itself (Certification and Endorsement). Although the security that PGP provides is proven to be reliable, it has largely failed to garner large scale adoption. In this paper, we propose several novel contributions to address the aforementioned issues with PGP and associated Web of Trust. To address the subjectivity of the Web of Trust, we provide a new Certificate Format based on Bitcoin which allows a user to verify a PGP Certificate using Bitcoin identity-verification transactions - forming first degree trust relationships that are tied to actual values (i.e., number of Bitcoins transferred during transaction). Secondly, we present the design of a novel Distributed PGP key server that leverages the Bitcoin transaction blockchain to store and retrieve our Certificates.

  • From pretty good to great: Enhancing PGP using bitcoin and the blockchain
    Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), 2015
    Co-Authors: Duane Wilson, Giuseppe Ateniese
    Abstract:

    PGP is built upon a Distributed Web of Trust in which the trustworthiness of a user is established by others who can vouch through a digital signature for that particular identity. Preventing its wholesale adoption are a number of inherent weaknesses to include (but not limited to) the following: 1) Trust Relationships are built on a subjective honor system, 2) Only first degree relationships can be fully trusted, 3) Levels of trust are difficult to quantify with actual values, and 4) Issues with the Web of Trust itself (Certification and Endorsement). Although the security that PGP provides is proven to be reliable, it has largely failed to garner large scale adoption. In this paper, we propose several novel contributions to address the aforementioned issues with PGP and associated Web of Trust. To address the subjectivity of the Web of Trust, we provide a new Certificate Format based on Bitcoin which allows a user to verify a PGP Certificate using Bitcoin identity-verification transactions - forming first degree trust relationships that are tied to actual values (i.e., number of Bitcoins transferred during transaction). Secondly, we present the design of a novel Distributed PGP key server that leverages the Bitcoin transaction blockchain to store and retrieve Bitcoin-Based PGP Certificates. Lastly, we provide a web prototype application that demonstrates several of these capabilities in an actual environment.

Jerzy Pejaś - One of the best experts on this subject based on the ideXlab platform.

  • A Practical Certificate and Identity Based Encryption Scheme and Related Security Architecture
    2013
    Co-Authors: Tomasz Hyla, Jerzy Pejaś
    Abstract:

    Group encryption schemes based on general access structures can be used to build advanced IT systems, which store and manage confidential documents. The paper proposes a reference architecture of public key cryptography infrastructure required to implement CIBE-GAS scheme. The CIBE-GAS scheme is a Certificate-based group-oriented encryption scheme with an effective secret sharing scheme based on general access structure and bilinear pairings. The security architecture required to implement the scheme must be compliant with common standards and technical specifications, e.g. X.509 Certificate Format and XML-encryption standard for messages. In order to encrypt arbitrary-length messages, we also suggest a new CIBE-GAS-H scheme with a key encapsulation mechanism based on the techniques of Bentahar et al., and combined with one-time symmetric-key encryption.

  • CISIM - A Practical Certificate and Identity Based Encryption Scheme and Related Security Architecture
    Computer Information Systems and Industrial Management, 2013
    Co-Authors: Tomasz Hyla, Jerzy Pejaś
    Abstract:

    Group encryption schemes based on general access structures can be used to build advanced IT systems, which store and manage confidential documents. The paper proposes a reference architecture of public key cryptography infrastructure required to implement CIBE-GAS scheme. The CIBE-GAS scheme is a Certificate-based group-oriented encryption scheme with an effective secret sharing scheme based on general access structure and bilinear pairings. The security architecture required to implement the scheme must be compliant with common standards and technical specifications, e.g. X.509 Certificate Format and XML-encryption standard for messages. In order to encrypt arbitrary-length messages, we also suggest a new CIBE-GAS-H scheme with a key encapsulation mechanism based on the techniques of Bentahar et al., and combined with one-time symmetric-key encryption.

Feng Ji-qiang - One of the best experts on this subject based on the ideXlab platform.

  • Research on standard system for mutual trust and mutual recognition based on PKI/CA in E-government
    Journal of Shenzhen University Science and Engineering, 2012
    Co-Authors: Feng Ji-qiang
    Abstract:

    The significance and principles of establishing a standard system for multi-certification authority(multi-CA) mutual trust and recognition of E-government in China are described based on the development status of the domestic and international electronic authentication standardization.A preliminary framework of standard system for mutual trust and recognition based on PKI/CA is proposed by taking into account legal,managerial and technological issues to meet the demands of E-government in Shenzhen.Key technical standards of digital Certificate Format,application interface and Certificate revocation lists are also thoroughly studied and developed to support multi-CA compatible applications.

Feng Jiqiang - One of the best experts on this subject based on the ideXlab platform.

  • research on standard system for mutual trust and mutual recognition based on pki ca in e government
    Journal of Shenzhen University Science and Engineering, 2012
    Co-Authors: Feng Jiqiang
    Abstract:

    The significance and principles of establishing a standard system for multi-certification authority(multi-CA) mutual trust and recognition of E-government in China are described based on the development status of the domestic and international electronic authentication standardization.A preliminary framework of standard system for mutual trust and recognition based on PKI/CA is proposed by taking into account legal,managerial and technological issues to meet the demands of E-government in Shenzhen.Key technical standards of digital Certificate Format,application interface and Certificate revocation lists are also thoroughly studied and developed to support multi-CA compatible applications.