Let's Revoke: Scalable Global Certificate Revocation
Trevor Smith, Luke Dickenson, Kent E. Seamons
Abstract
—Current revocation strategies have numerous issues that prevent their widespread adoption and use, including scalability, privacy, and new infrastructure requirements. Consequently, revocation is often ignored, leaving clients vulnerable to man-in-the-middle attacks. This paper presents Let’s Revoke, a scalable global revocation strategy that addresses the concerns of current revocation checking. Let’s Revoke introduces a new unique identifier to each certificate that serves as an index to a dynamically-sized bit vector containing revocation status information. The bit vector approach enables significantly more efficient revocation checking for both clients and certificate authorities. We compare Let’s Revoke to existing revocation schemes and show that it requires less storage and network bandwidth than other systems, including those that cover only a fraction of the global certificate space. We further demonstrate through simulations that Let’s Revoke scales linearly up to ten billion certificates, even during mass revocation events.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 915deb75-a5eb-40e0-aeab-9cf6bd588039Cited by top-tier papers10
- Private Blocklist Lookups with ChecklistDmitry Kogan, Henry Corrigan-GibbsUSENIX Security 2021 · 104 citations
- EVOKE: Efficient Revocation of Verifiable Credentials in IoT NetworksCarlo Mazzocca, Abbas Acar, A. Selcuk Uluagac, Rebecca MontanariUSENIX Security 2024 · 22 citations
- On-device IoT Certificate Revocation Checking with Small Memory and Low LatencyXiaofeng Shi, Shouqian Shi, Minmei Wang, Jonne Kaunisto et al.CCS 2021 · 18 citations
- Rusted Anchors: A National Client-Side View of Hidden Root CAs in the Web PKI EcosystemYiming Zhang, Baojun Liu, Chaoyi Lu, Zhou Li et al.CCS 2021 · 16 citations
- CTng: Secure Certificate and Revocation TransparencyJie Kong, James Damon, Hemi Leibowitz, Ewa Syta et al.NDSS 2026 · 5 citations
Builds on3
- Let's Encrypt: An Automated Certificate Authority to Encrypt the Entire WebJosh Aas, Richard Barnes, Benton Case, Zakir Durumeric et al.CCS 2019 · 138 citations
- CRLite: A Scalable System for Pushing All TLS Revocations to All BrowsersJames Larisch, David R. Choffnes, Dave Levin, Bruce M. Maggs et al.S&P 2017 · 105 citations
- Tracking Certificate Misissuance in the WildDeepak Kumar, Zhengping Wang, Matthew Hyder, Joseph Dickinson et al.S&P 2018 · 86 citations
Related papers
- AccuRevoke: Enhancing Certificate Revocation with Distributed Cryptographic AccumulatorsMunshi Rejwan Ala Muid, Taejoong Chung, Thang HoangS&P 2025
- Reliable and Decentralized Certificate Revocation via DNS: The Case for RevDNSTaejoong Chung, Dave Levin, Protick BhowmickSIGCOMM 2025 · 2 citations
- How Effective is Multiple-Vantage-Point Domain Control Validation?Grace H. Cimaszewski, Henry Birge-Lee, Liang Wang, Jennifer Rexford et al.USENIX Security 2023
- Let's Downgrade Let's EncryptTianxiang Dai, Haya Schulmann, Michael WaidnerCCS 2021 · 16 citations
- Experiences Deploying Multi-Vantage-Point Domain Validation at Let's EncryptHenry Birge-Lee, Liang Wang, Daniel McCarney, Roland Shoemaker et al.USENIX Security 2021 · 23 citations
