AccuRevoke: Enhancing Certificate Revocation with Distributed Cryptographic Accumulators
Munshi Rejwan Ala Muid, Taejoong Chung, Thang Hoang
Abstract
Certificate revocation is essential for maintaining the security of the Public Key Infrastructure (PKI), ensuring that compromised or untrustworthy certificates are invalidated promptly. Traditional revocation mechanisms like Certificate Revocation Lists (CRLs) and the Online Certificate Status Protocol (OCSP) face significant challenges, including scalability issues, high bandwidth consumption, privacy concerns, and reliance on centralized infrastructure that can become points of failure. In this paper, we introduce AccuRevoke, a novel revocation scheme that leverages cryptographic accumulators and edge computing to address these challenges effectively. Accu Revoke enables clients to verify the revocation status of certificates efficiently without the need to contact Certificate Authorities (CAs) directly for each validation. By utilizing distributed accumulators and threshold cryptography, Accu Revoke ensures authenticity and integrity of revocation information, even when responses are generated by third-party Edge Compute Providers (ECPs). Our scheme significantly reduces bandwidth consumption by providing compact revocation proofs-approximately 21 bytes for membership proofs and 61 bytes for non-membership proofs-which are substantially smaller than traditional OCSP responses. To further optimize performance, especially in generating non-membership witnesses, we employ GPU acceleration, achieving considerable improvements in processing times. We compare AccuRevoke with existing revocation mechanisms, demonstrating advantages in bandwidth efficiency, reliability, auditability, and potential enhancements in privacy. Our evaluation shows that Accu Revoke offers a scalable and practical solution for revocation checking, improving the security and performance of TLSIPKI deployments. We plan to open-source our design and implementation to facilitate adoption and encourage further research in this area.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get f828da3e-ad27-48a4-b45f-97c084f7df8aRelated papers
- EVOKE: Efficient Revocation of Verifiable Credentials in IoT NetworksCarlo Mazzocca, Abbas Acar, A. Selcuk Uluagac, Rebecca MontanariUSENIX Security 2024 · 22 citations
- Let's Revoke: Scalable Global Certificate RevocationTrevor Smith, Luke Dickenson, Kent E. SeamonsNDSS 2020
- Reliable and Decentralized Certificate Revocation via DNS: The Case for RevDNSTaejoong Chung, Dave Levin, Protick BhowmickSIGCOMM 2025 · 2 citations
- On-device IoT Certificate Revocation Checking with Small Memory and Low LatencyXiaofeng Shi, Shouqian Shi, Minmei Wang, Jonne Kaunisto et al.CCS 2021 · 18 citations
- CRLite: A Scalable System for Pushing All TLS Revocations to All BrowsersJames Larisch, David R. Choffnes, Dave Levin, Bruce M. Maggs et al.S&P 2017 · 105 citations
