Blockchain-based Certificate Management with Multi-Party Authentication

Lei Xu, Xue Song, Jipeng Hou, Liehuang Zhu

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

The authenticity and reliability of user identity are the premise of secure network communication. Public key infrastructure (PKI) issues certificates through certificate authority (CA) and provides users with secure identity management services. In traditional PKI systems, the CA is given much power, and the compromise of CA will lead to a single point of failure. How to prevent the CA from issuing fraudulent certificates has become a vital issue. In this paper, we propose a blockchain-based certificate management scheme. The proposed scheme separates the identity verification process from certificate issuance, and distributes the verification task to multiple registration authorities (RAs). This can prevent the attacker from issuing fraudulent certificates by controlling one CA or RA. Besides, the proposed scheme requires the subject of a certificate to store information about the certificate on the blockchain. Only if the corresponding record can be found on the blockchain, the certificate will be considered validate. As a result, the impersonation attack can be prevented. Simulation results demonstrate that the proposed certificate management scheme is feasible.

Original languageEnglish
Title of host publicationProceedings - 2023 6th International Conference on Information and Computer Technologies, ICICT 2023
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages211-219
Number of pages9
ISBN (Electronic)9798350300956
DOIs
Publication statusPublished - 2023
Event6th International Conference on Information and Computer Technologies, ICICT 2023 - Raleigh, United States
Duration: 24 Mar 202326 Mar 2023

Publication series

NameProceedings - 2023 6th International Conference on Information and Computer Technologies, ICICT 2023

Conference

Conference6th International Conference on Information and Computer Technologies, ICICT 2023
Country/TerritoryUnited States
CityRaleigh
Period24/03/2326/03/23

Keywords

  • aggregated signature
  • blockchain
  • certificate management
  • impersonation attack
  • public key infrastructure

Fingerprint

Dive into the research topics of 'Blockchain-based Certificate Management with Multi-Party Authentication'. Together they form a unique fingerprint.

Cite this