vix.ing · top · new · best · stats · spec

Certificate Revocation Paradigms

1999/09/17 by Jan Willemson, Willemson, Jan
Computer Science · #Advanced Database Systems and Queries #Complexity and Algorithms in Graphs #Cryptography and Data Security #Cryptography and Security (cs.CR) #E.3 #FOS: Computer and information sciences #H.3 #cs.CR

paper · pdf · doi:10.48550/arxiv.cs/9909012

Tech report on 14 pages, 2 figures

arxiv created 1999/09/17 · openalex publication_date 1999/09/17 · arxiv updated 2009/11/30 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/28

Abstract

Research in the field of electronic signature confirmation has been active for some 20 years now. Unfortunately present certificate-based solutions also come from that age when no-one knew about online data transmission. The official standardized X.509 framework also depends heavily on offline operations, one of the most complicated ones being certificate revocation handling. This is done via huge Certificate Revocation Lists which are both inconvenient and expencive. Several improvements to these lists are proposed and in this report we try to analyze them briefly. We conclude that although it is possible to do better than in the original X.509 setting, none of the solutions presented this far is good enough.

Related