论文标题
使用分布式分类帐技术硬化X.509证书发行
Hardening X.509 Certificate Issuance using Distributed Ledger Technology
论文作者
论文摘要
使用X.509证书的加密通信协议的安全性取决于这些证书的正确性。本文提出了一个系统,该系统有助于确保X.509认证当局及其注册机构的正确操作。我们通过执行政策定义的,多方验证和证书签名请求的授权工作流程来实现这一目标。此外,我们的系统针对法医目的为此工作流提供了全部责任。作为实施的基础,我们利用分布式分类帐和智能合约框架HyperLeDger面料。我们的实施继承了对结构的强烈防篡改,从而增强了计算机流程的完整性,该过程可以执行证书签名请求的验证和授权以及证书发行期间收集的元数据的验证和授权。
The security of cryptographic communication protocols that use X.509 certificates depends on the correctness of those certificates. This paper proposes a system that helps to ensure the correct operation of an X.509 certification authority and its registration authorities. We achieve this goal by enforcing a policy-defined, multi-party validation and authorization workflow of certificate signing requests. Besides, our system offers full accountability for this workflow for forensic purposes. As a foundation for our implementation, we leverage the distributed ledger and smart contract framework Hyperledger Fabric. Our implementation inherits the strong tamper-resistance of Fabric which strengthens the integrity of the computer processes that enforce the validation and authorization of the certificate signing request, and of the metadata collected during certificate issuance.