TwinPeaks: An approach for certificateless public key distribution for the internet and internet of things

被引:5
|
作者
Cho, Eunsang [1 ]
Kim, Jeongnyeo [2 ]
Park, Minkyung [1 ]
Lee, Hyeonmin [1 ]
Hamm, Chorom [1 ]
Park, Soobin [1 ]
Sohn, Sungmin [1 ]
Kang, Minhyeok [1 ]
Kwon, Ted Taekyoung [1 ]
机构
[1] Seoul Natl Univ, 1 Gwanak Ro, Seoul 08826, South Korea
[2] Elect & Telecommun Res Inst, 218 Gajeong Ro, Daejeon 34129, South Korea
基金
新加坡国家研究基金会;
关键词
Public key infrastructure; Certificateless public key cryptography; Public key distribution; Internet of things; ENCRYPTION; PKI;
D O I
10.1016/j.comnet.2020.107268
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The current public key infrastructure (PKI) has thorny issues like the overhead of certificate revocations and the consequence of fraudulent certificates. To address such issues, we propose TwinPeaks, which is an infrastructure to distribute public keys of named entities on the Internet and the Internet of Things (IoT). TwinPeaks leverages certificateless public key cryptography (CL-PKC), where a key generation center (KGC) cannot know the private key of its member, and hence its compromise will not result in member key leakage. By extending CL-PKC, the public key of an entity becomes dependent on any combination of its networking parameters; thus TwinPeaks can thwart spoofing attacks systematically. With TwinPeaks, the public key of every named entity is distributed online while addressing the PKI's vulnerabilities. TwinPeaks has public key servers, which constitute the domain name system (DNS)-like hierarchical tree structure. For each parent-child link in the tree, the parent node serves as a key generation center (KGC), and its child nodes set up their own public/secret key pairs by interacting with the KGC as proposed in CL-PKC. In this way, every named entity (e.g., a domain name) has its own public/secret key pair. Thus, a public key of an entity will be provided to a user by its key server as the DNS response is returned to the user by its DNS server. TwinPeaks removes certificates and hence has no revocation overhead. Instead, each named entity should keep/update its networking parameters and public key up-to-date in its DNS server and key server, respectively. By making its public key depend on both its Internet protocol (IP) address and domain name, the compromise of a single entity (e.g., a DNS or key server) cannot lead to successful impersonation. TwinPeaks achieves scalable distribution of public keys since public keys can be cached long term. We also show that TwinPeaks can be applied to the IoT environments by extending the naming scheme.
引用
收藏
页数:15
相关论文
共 50 条
  • [41] Certificateless Searchable Encryption With Trapdoor Unlinkability for Industrial Internet of Things
    Sun, Lixue
    Xu, Chunxiang
    Zhang, Xiaojun
    Zeng, Fugeng
    IEEE SYSTEMS JOURNAL, 2023, 17 (03): : 4521 - 4532
  • [42] A new provably secure certificateless signature scheme for Internet of Things
    Du, Hongzhen
    Wen, Qiaoyan
    Zhang, Shanshan
    Gao, Mingchu
    Ad Hoc Networks, 2020, 100
  • [43] Certificateless Hybrid Signcryption by a Novel Protocol Applied to Internet of Things
    Zhang, Wenzhan
    Zhang, Yanhui
    Guo, Chong
    An, Qi
    Guo, Yuming
    Liu, Ximing
    Zhang, Shijun
    Huang, Junjia
    COMPUTATIONAL INTELLIGENCE AND NEUROSCIENCE, 2022, 2022
  • [44] A new provably secure certificateless signature scheme for Internet of Things
    Du, Hongzhen
    Wen, Qiaoyan
    Zhang, Shanshan
    Gao, Mingchu
    AD HOC NETWORKS, 2020, 100
  • [45] An Efficient Scheme for Industrial Internet of Things Using Certificateless Signature
    Muhammad, Ali
    Ul Amin, Noor
    Ullah, Insaf
    Alsanad, Ahmed
    Hussain, Saddam
    Al-Hadhrami, Suheer
    Uddin, M. Irfan
    Khattak, Hizbullah
    Khan, Muhammad Asghar
    MATHEMATICAL PROBLEMS IN ENGINEERING, 2021, 2021
  • [46] An Efficient and Provably Secure Certificateless Protocol for Industrial Internet of Things
    Rafique, Farva
    Obaidat, Mohammad S.
    Mahmood, Khalid
    Ayub, Muhammad Faizan
    Ferzund, Javed
    Chaudhry, Shehzad Ashraf
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2022, 18 (11) : 8039 - 8046
  • [47] Veritaa-IoT: A Distributed Public Key Infrastructure for the Internet of Things
    Schaerer, Jakob
    Zumbrunn, Severin
    Braun, Torsten
    2022 IFIP NETWORKING CONFERENCE (IFIP NETWORKING), 2022,
  • [48] Lightweight public key infrastructure for the Internet of Things: A systematic literature review
    El-Hajj, Mohammed
    Beune, Pim
    JOURNAL OF INDUSTRIAL INFORMATION INTEGRATION, 2024, 41
  • [49] Quantum-Safe Lattice-Based Certificateless Anonymous Authenticated Key Agreement for Internet of Things
    Wei, Guanglu
    Fan, Kai
    Zhang, Kuan
    Wang, Haoyang
    Li, Hui
    Yang, Yintang
    IEEE INTERNET OF THINGS JOURNAL, 2024, 11 (05): : 9213 - 9225
  • [50] Services and Key Technologies of the Internet of Things
    Xing Xiaojiang
    ZTECommunications, 2010, 8 (02) : 26 - 29