15th Annual Computer Security Applications Conference
December 6-10, 1999
Phoenix, Arizona


A Model of Certificate Revocation

David A. Cooper, david.cooper@nist.gov
Computer Security Division
National Institute of Standards and Technology
100 Bureau Dr. STOP 8930
Gaithersburg, MD 20899-8930

keywords: certificate revocation, certificate revocation list, certification authority, CRL

This paper presents a model for the distribution of revocation information using certificate revocation lists (CRLs). This model is used to highlight inefficiencies in the “traditional” method of distributing certificate status information using CRLs. Two alternative CRL-based revocation distribution mechanisms, over-issued CRLs and segmented CRLs, are then presented. The original model is then expanded to encompass each of the alternative mechanisms and these expanded models are used to demonstrate the advantages of the alternative mechanisms to the “traditional” method. Finally, the paper offers some suggestions for choosing the best CRL-based revocation distribution mechanism for any particular environment.