KORGAN: An Efficient PKI Architecture Based on PBFT Through Dynamic Threshold Signatures

dc.cclicenceCC-BY-NCen
dc.contributor.authorKiraz, Mehmet Sabir
dc.contributor.authorKubilay, Murat
dc.contributor.authorMantar, Haci Ali
dc.date.acceptance2020-06-08
dc.date.accessioned2020-06-09T10:26:22Z
dc.date.available2020-06-09T10:26:22Z
dc.date.issued2020-08-12
dc.descriptionThe file attached to this record is the author's final peer reviewed version.en
dc.description.abstractDuring the last decade, several misbehaving Certificate Authorities (CA) have issued fraudulent TLS certificates allowing MITM kinds of attacks which result in serious security incidents. In order to avoid such incidents, Yakubov et al. recently proposed a new PKI architecture where CAs issue, revoke, and validate X.509 certificates on a public blockchain. However, in their proposal TLS clients are subject to MITM kinds of attacks and certificate transparency is not fully provided. In this paper, we eliminate the issues of the Yakubov et al.’s scheme and propose a new PKI architecture based on permissioned blockchain with PBFT consensus mechanism where the consensus nodes utilize a dynamic threshold signature scheme to generate signed blocks. In this way, the trust to the intermediary entities can be completely eliminated during certificate validation. Our scheme enjoys the dynamic property of the threshold signature because TLS clients do not have to change the verification key even if the validator set is dynamic. We implement our proposal on private Ethereum network to demonstrate the experimental results. The results show that our proposal has negligible overhead during TLS handshake. The certificate validation duration is less than the duration in the conventional PKI and Yakubov et al.’s scheme.en
dc.funderNo external funderen
dc.identifier.citationKiraz, M.S., Kubilay, M., Mantar, H.A. (2020) KORGAN: An Efficient PKI Architecture Based on PBFT Through Dynamic Threshold Signatures. The Computer Journal, 64 (4), pp. 564-574en
dc.identifier.doihttps://doi.org/10.1093/comjnl/bxaa081
dc.identifier.urihttps://dora.dmu.ac.uk/handle/2086/19743
dc.language.isoenen
dc.peerreviewedYesen
dc.publisherOxford University Pressen
dc.researchinstituteCyber Technology Institute (CTI)en
dc.subjectSSL/TLSen
dc.subjectPKIen
dc.subjectCertificate Transparencyen
dc.subjectPBFTen
dc.subjectDynamic Threshold Signaturesen
dc.titleKORGAN: An Efficient PKI Architecture Based on PBFT Through Dynamic Threshold Signaturesen
dc.typeArticleen

Files

Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
korgan.pdf
Size:
315.38 KB
Format:
Adobe Portable Document Format
Description:
License bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
4.2 KB
Format:
Item-specific license agreed upon to submission
Description: