2020/04/15 by Kinkelin, Holger, von Seck, Richard, Rudolf, Christoph +1 · 1 citation
#Cryptography and Security (cs.CR) #FOS: Computer and information sciences #FOS: Electrical engineering #Systems and Control (eess.SY) #electronic engineering #information engineering
paper · doi:10.48550/arxiv.2004.07063
The security of cryptographic communication protocols that use X.509 certificates depends on the correctness of those certificates. This paper proposes a system that helps to ensure the correct operation of an X.509 certification authority and its registration authorities. We achieve this goal by enforcing a policy-defined, multi-party validation and authorization workflow of certificate signing requests. Besides, our system offers full accountability for this workflow for forensic purposes. As a foundation for our implementation, we leverage the distributed ledger and smart contract framework Hyperledger Fabric. Our implementation inherits the strong tamper-resistance of Fabric which strengthens the integrity of the computer processes that enforce the validation and authorization of the certificate signing request, and of the metadata collected during certificate issuance.