RIKE+: using revocable identities to support key escrow in public key infrastructures with flexibility. Issue 2 (1st March 2015)
- Record Type:
- Journal Article
- Title:
- RIKE+: using revocable identities to support key escrow in public key infrastructures with flexibility. Issue 2 (1st March 2015)
- Main Title:
- RIKE+: using revocable identities to support key escrow in public key infrastructures with flexibility
- Authors:
- Lin, Jingqiang
Zhu, Wen‐Tao
Wang, Qiongxiao
Zhang, Nan
Jing, Jiwu
Gao, Neng - Abstract:
- Abstract : Public key infrastructures (PKIs) are proposed to provide various security services. Some security services such as confidentiality require key escrow in certain scenarios, whereas some others such as non‐repudiation and authentication usually prohibit key escrow. Moreover, these two conflicting requirements can coexist for one PKI user. The popular solution in which each user has two different certificates and an escrow authority backs up all escrowed private keys faces the problems of efficiency and scalability. In this study, a novel key management infrastructure called RIKE + is proposed to integrate the 'inherent key escrow' of identity‐based encryption (IBE) into PKIs. In RIKE+, (the hash value of) a user's PKI certificate also serves as a 'revocable identity' to derive the user's IBE public key, and the revocation of this IBE key pair is achieved by the certificate revocation of PKIs. Therefore the certificate binds the user with two key pairs, one of which is escrowed inherently and the other is not. Furthermore, RIKE+ employs chameleon hash to flexibly control the relationship between the certificate and the IBE key pair. In the case of certificate renewal and revocation, chameleon hash enables RIKE+ to manipulate the hash value of the new certificate, so the user's IBE key pair is not unconditionally changed unless it is necessary. RIKE+ is an effective certificate‐based solution compatible with traditional PKIs and can be built on existing X.509 PKIs.
- Is Part Of:
- IET information security. Volume 9:Issue 2(2015)
- Journal:
- IET information security
- Issue:
- Volume 9:Issue 2(2015)
- Issue Display:
- Volume 9, Issue 2 (2015)
- Year:
- 2015
- Volume:
- 9
- Issue:
- 2
- Issue Sort Value:
- 2015-0009-0002-0000
- Page Start:
- 136
- Page End:
- 147
- Publication Date:
- 2015-03-01
- Subjects:
- public key cryptography
RIKE + -- revocable identities -- public key infrastructures -- security services -- key escrow -- escrow authority -- escrowed private keys -- key management infrastructure -- identity‐based encryption -- PKI certificate -- IBE public key -- flexibly control -- chameleon hash -- certificate renewal -- certificate revocation
Computer security -- Periodicals
Cryptography -- Periodicals
Computer networks -- Security measures -- Periodicals
Database security -- Periodicals
005.8 - Journal URLs:
- https://ietresearch.onlinelibrary.wiley.com/journal/17518717 ↗
http://digital-library.theiet.org/content/journals/iet-ifs ↗
http://www.ietdl.org/IET-IFS ↗
http://www.theiet.org/ ↗ - DOI:
- 10.1049/iet-ifs.2013.0552 ↗
- Languages:
- English
- ISSNs:
- 1751-8709
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 4363.252660
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 17405.xml