Next: Transparency.
Up: Notable Features
Previous: CA-based Key Generation.
The notoriously difficult revocation problem is greatly simplified
in mRSA. In order to revoke a user's public key, it suffices to
notify that user's SEM. Each SEM merely maintains a list of
revoked users which is consulted upon every service request.
Our implementation uses standard X.509 Certificate Revocation Lists (CRL's)
for this purpose.
Gene Tsudik
2001-05-10