Paper 2025/610
Clubcards for the WebPKI: smaller certificate revocation tests in theory and practice
Abstract
CRLite is a low-bandwidth, low-latency, privacy-preserving mechanism for distributing certificate revocation data. A CRLite aggregator periodically encodes revocation data into a compact static hash set, or membership test, which can can be downloaded by clients and queried privately. We present a novel data-structure for membership tests, which we call a clubcard, and we evaluate the encoding efficiency of clubcards using data from Mozilla's CRLite infrastructure.
As of November 2024, the WebPKI contains over 900 million valid certificates and over 8 million revoked certificates. We describe an instantiation of CRLite that encodes the revocation status of these certificates in a 6.7 MB package. This is
Metadata
- Available format(s)
-
PDF
- Category
- Applications
- Publication info
- Published elsewhere. IEEE S&P 2025
- Keywords
- certificate revocationcrlitepublic key infrastructurewebpki
- Contact author(s)
- jschanck @ mozilla com
- History
- 2025-04-08: approved
- 2025-04-03: received
- See all versions
- Short URL
- https://ia.cr/2025/610
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2025/610, author = {John M. Schanck}, title = {Clubcards for the {WebPKI}: smaller certificate revocation tests in theory and practice}, howpublished = {Cryptology {ePrint} Archive, Paper 2025/610}, year = {2025}, url = {https://eprint.iacr.org/2025/610} }