Concepedia

Publication | Open Access

COCA: A Secure Distributed On-line Certification Authority

256

Citations

0

References

2002

Year

TLDR

COCA’s protocols operate under extremely weak assumptions: no timing guarantees, only intermittent reliable channels, and up to t faulty or compromised replicas among 3t + 1 servers. COCA is the first system to integrate a Byzantine quorum system with proactive recovery to defend against mobile adversaries that compromise one replica at a time. To combine fault‑tolerance and security, new proactive recovery protocols were developed. COCA is a fault‑tolerant, secure on‑line certification authority deployed in LAN and Internet environments, and experimental results quantitatively evaluate its cost and effectiveness.

Abstract

COCA is a fault-tolerant and secure on-line certification authority that has been built and deployed both in a local area network and in the Internet. Extremely weak assumptions characterize environments in which COCA’s protocols execute correctly: no assumption is made about execution speed and message delivery delays; channels are expected to exhibit only intermittent reliability; and with 3t + 1 COCA servers up to t may be faulty or compromised. COCA is the first system to integrate a Byzantine quorum system (used to achieve availability) with proactive recovery (used to defend against mobile adversaries which attack, compromise, and control one replica for a limited period of time before moving on to another). In addition to tackling problems associated with combining fault-tolerance and security, new proactive recovery protocols had to be developed. Experimental results give a quantitative evaluation for the cost and effectiveness of the protocols.