Skip to main content

2018 | OriginalPaper | Buchkapitel

Towards a Smart Contract-Based, Decentralized, Public-Key Infrastructure

verfasst von : Christos Patsonakis, Katerina Samari, Mema Roussopoulos, Aggelos Kiayias

Erschienen in: Cryptology and Network Security

Verlag: Springer International Publishing

Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.

search-config
loading …

Abstract

Public-key infrastructures (PKIs) are an integral part of the security foundations of digital communications. Their widespread deployment has allowed the growth of important applications, such as, internet banking and e-commerce. Centralized PKIs (CPKIs) rely on a hierarchy of trusted Certification Authorities (CAs) for issuing, distributing and managing the status of digital certificates, i.e., unforgeable data structures that attest to the authenticity of an entity’s public key. Unfortunately, CPKI’s have many downsides in terms of security and fault tolerance and there have been numerous security incidents throughout the years. Decentralized PKIs (DPKIs) were proposed to deal with these issues as they rely on multiple, independent nodes. Nevertheless, decentralization raises other concerns such as what are the incentives for the participating nodes to ensure the service’s availability.
In our work, we leverage the scalability, as well as, the built-in incentive mechanism of blockchain systems and propose a smart contract-based DPKI. The main barrier in realizing a smart contract-based DPKI is the size of the contract’s state which, being its most expensive resource to access, should be minimized for a construction to be viable. We resolve this problem by proposing and using in our DPKI a public-state cryptographic accumulator with constant size, a cryptographic tool which may be of independent interest in the context of blockchain protocols. We also are the first to formalize the DPKI design problem in the Universal Composability (UC) framework and formally prove the security of our construction under the strong RSA assumption in the Random Oracle model and the existence of an ideal smart contract functionality.

Sie haben noch keine Lizenz? Dann Informieren Sie sich jetzt über unsere Produkte:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Anhänge
Nur mit Berechtigung zugänglich
Fußnoten
1
As we explained in Sect. 5, a set \(X_2'\) is derived by \(DBstate'\) in the following way: For any record of the form \((\mathsf {Register}, id, pk, i, W_1, W_2,W_3)\), (idia) is added to \(X_2\) and for any record of the form \((\mathsf {Revoke}, id, pk, i)\), (idid) is added to \(X_2\).
 
Literatur
10.
Zurück zum Zitat Avramidis, A., Kotzanikolaou, P., Douligeris, C., Burmester, M.: Chord-PKI: a distributed trust infrastructure based on P2P networks. Comput. Netw. 56, 378–398 (2012)CrossRef Avramidis, A., Kotzanikolaou, P., Douligeris, C., Burmester, M.: Chord-PKI: a distributed trust infrastructure based on P2P networks. Comput. Netw. 56, 378–398 (2012)CrossRef
12.
Zurück zum Zitat Baldimtsi, F., et al.: Accumulators with applications to anonymity-preserving revocation. In: EuroS&P (2017) Baldimtsi, F., et al.: Accumulators with applications to anonymity-preserving revocation. In: EuroS&P (2017)
16.
Zurück zum Zitat Canetti, R.: Universally composable security: a new paradigm for cryptographic protocols. IACR Cryptology ePrint Archive 2000:67 (2000) Canetti, R.: Universally composable security: a new paradigm for cryptographic protocols. IACR Cryptology ePrint Archive 2000:67 (2000)
17.
18.
Zurück zum Zitat Datta, A., Hauswirth, M., Aberer, K.: Beyond “web of trust”: enabling P2P e-commerce. In: CEC 2003, pp. 303–312 (2003) Datta, A., Hauswirth, M., Aberer, K.: Beyond “web of trust”: enabling P2P e-commerce. In: CEC 2003, pp. 303–312 (2003)
20.
Zurück zum Zitat Ellison, C., Schneier, B.: Ten risks of PKI: what you’re not being told about public key infrastructure (2000) Ellison, C., Schneier, B.: Ten risks of PKI: what you’re not being told about public key infrastructure (2000)
21.
Zurück zum Zitat Fromknecht, C., Velicanu, D., Yakoubov, S.: A decentralized public key infrastructure with identity retention. IACR (2014) Fromknecht, C., Velicanu, D., Yakoubov, S.: A decentralized public key infrastructure with identity retention. IACR (2014)
23.
Zurück zum Zitat Garay, J., Kiayias, A., Leonardos, N.: The bitcoin backbone protocol with chains of variable diculty. IACR Cryptology ePrint Archive (2016) Garay, J., Kiayias, A., Leonardos, N.: The bitcoin backbone protocol with chains of variable diculty. IACR Cryptology ePrint Archive (2016)
25.
Zurück zum Zitat Gipp, B., Meuschke, N., Gernandt, A.: Decentralized trusted timestamping using the crypto currency bitcoin. CoRR, abs/1502.04015 (2015) Gipp, B., Meuschke, N., Gernandt, A.: Decentralized trusted timestamping using the crypto currency bitcoin. CoRR, abs/1502.04015 (2015)
27.
Zurück zum Zitat Karakaya, M., Korpeoglu, I., Ulusoy, Ö.: Free riding in peer-to-peer networks. IEEE Internet Comput. 13(2), 92–98 (2009)CrossRef Karakaya, M., Korpeoglu, I., Ulusoy, Ö.: Free riding in peer-to-peer networks. IEEE Internet Comput. 13(2), 92–98 (2009)CrossRef
28.
Zurück zum Zitat Lesueur, F., Me, L., Tong, V.V.T.: An efficient distributed PKI for structured P2P networks. In IEEE P2PC (2009) Lesueur, F., Me, L., Tong, V.V.T.: An efficient distributed PKI for structured P2P networks. In IEEE P2PC (2009)
34.
Zurück zum Zitat Reiter, M.K.: Franklin, M.K., Lacy, J.B., Wright, R.N.: The \(\omega \) key management service. In: CCS 1996 (1996) Reiter, M.K.: Franklin, M.K., Lacy, J.B., Wright, R.N.: The \(\omega \) key management service. In: CCS 1996 (1996)
37.
Zurück zum Zitat Wouhaybi, R.H., Campbell, A.T.: Keypeer: a scalable, resilient distributed public-key system using chord (2008) Wouhaybi, R.H., Campbell, A.T.: Keypeer: a scalable, resilient distributed public-key system using chord (2008)
38.
Zurück zum Zitat Yüce, E., Selçuk, A.A.: Server notaries: a complementary approach to the web PKI trust model. IACR Cryptology ePrint Archive 2016:126 (2016) Yüce, E., Selçuk, A.A.: Server notaries: a complementary approach to the web PKI trust model. IACR Cryptology ePrint Archive 2016:126 (2016)
39.
Zurück zum Zitat Zhou, L., Schneider, F.B., Van Renesse, R.: COCA: a secure distributed online certification authority. ACM Trans. Comput. Syst. 20, 329–368 (2002)CrossRef Zhou, L., Schneider, F.B., Van Renesse, R.: COCA: a secure distributed online certification authority. ACM Trans. Comput. Syst. 20, 329–368 (2002)CrossRef
Metadaten
Titel
Towards a Smart Contract-Based, Decentralized, Public-Key Infrastructure
verfasst von
Christos Patsonakis
Katerina Samari
Mema Roussopoulos
Aggelos Kiayias
Copyright-Jahr
2018
DOI
https://doi.org/10.1007/978-3-030-02641-7_14