Delegated Path Validation Explained

Delegated Path Validation (DPV) is a cryptographic method used to offload the task of validating the certification path of digital certificates from the client to a trusted server. This process is integral to various security protocols that rely on Public Key Infrastructure (PKI). DPV aim to enhance the efficiency of certification path validation by leveraging a server dedicated to this task, which provides validation results to the client. This approach is particularly useful in resource-constrained environments where clients may not have the computational power to perform extensive certificate validation themselves.[1]

Certificate path validation

See main article: Certification path validation algorithm. Certificate path validation is a crucial process in PKI that ensures the authenticity and trustworthiness of a digital certificate. This process is standardized in and involves verifying a chain of certificates, starting from the certificate being validated (the end-entity certificate) up to a trusted root certificate authority (CA).[2] The validation process includes several key steps:

If all these checks are successfully passed, the certificate path is considered valid, and the end-entity certificate can be trusted.

Validation policy

DPV allows a server to handle the entire process of path validation based on a set of predefined rules known as a validation policy. This policy may involve multiple trust anchors. A trust anchor is characterized by a public key, a Certificate Authority (CA) name, and a validity period; it may also have additional constraints.[3] A self-signed certificate can be used to designate the public key, issuer name, and the validity period for a trust anchor. Additional constraints for trust anchors can be defined, such as certification policy constraints or naming constraints. These constraints can also be part of self-signed certificates. For successful path validation, a valid certification path must be established between the end-entity certificate and a trust anchor, ensuring that none of the certificates in the path are expired or revoked, and all constraints on the path must be met. A validation policy consists of three main components:

  1. Certification path requirements: these define the sequence of trust anchors needed to start the certification path processing and the initial conditions for validation;
  2. Revocation requirements: these specify the checks needed on the end-entity and CA certificates to ensure they have not been revoked;
  3. End-entity certificate specific requirements: these may require the end-entity certificate to include specific extensions with certain types or values.

Protocol requirements

specifies several key requirements to ensure effective and secure delegated path validation.

Firstly, if a client requests a specific validation policy that the DPV server does not support, the server must return an error. This ensures that the client is aware that the requested policy cannot be applied. If the client does not specify a validation policy, the server must indicate which validation policy was used in the response. This transparency allows clients to understand the basis on which the validation was performed.

Validation policies can be complex and may include parameters such as root self-signed certificates. The DPV protocol must allow clients to include these policy-dependent parameters in their requests. However, it is expected that most clients will either reference a validation policy suitable for their application or accept the DPV server's default validation policy.

Clients can also request that the DPV server determines the certificate's validity at a specific time other than the current time. In such cases, the server must obtain revocation status information relevant to the specified validation time. If the necessary revocation status information is unavailable, the server must return a status indicating that the certificate is invalid, possibly providing additional details about the reason for invalidity.

For the validation to proceed, the certificate must be either directly provided in the request or unambiguously referenced by details such as the CA distinguished name, certificate serial number, and certificate hash. This ensures that the correct certificate is validated.

The DPV client must be capable of providing the validation server with useful certificates and revocation information related to each certificate being validated. This includes OCSP responses, CRLs, and delta CRLs, which are critical for checking the current status of certificates.

The DPV server must have access to the certificate that needs validation. If the certificate is not provided in the request, the server must obtain it and verify that it matches the reference provided by the client. In the response, the server must include either the certificate or a clear reference to it, especially in cases involving CA key compromises.

The response from the DPV server must indicate one of the following statuses:

If the certificate is not valid, the server must also provide the reason for this determination. Common reasons include the inability to construct a certification path, the constructed path failing the validation algorithm, or the certificate not being valid at the requested time, such as before its validity period begins or during a suspension.

Additionally, the DPV protocol must allow clients to request that the server includes extra information in its response. This extra information helps relying parties who do not trust the DPV server to be confident that the certificate validation was performed correctly. The DPV response must be bound to the DPV request, which can be achieved by including a one-way hash of the request in the response. This binding ensures that all request parameters were considered in building the response.

To ensure the client trusts the DPV server, the response must be authenticated. For the client to prove to third parties that the certificate validation was handled correctly, the DPV response must be digitally signed, except when reporting an error. The DPV server's certificate must authenticate the server, adding another layer of trust and security to the validation process.

Relaying, re-direction and multicasting

In certain network environments, particularly those with firewalls, a DPV server may encounter difficulties in obtaining all the necessary information to process a validation request. To address this, a DPV server can be configured to leverage the services of other DPV servers. In such scenarios, the client remains unaware that the primary DPV server is utilizing additional servers to fulfill the request. Essentially, the primary DPV server acts as a client to another DPV server, facilitating a more comprehensive validation process. Unlike end clients, DPV servers typically have more substantial computing and memory resources, enabling them to employ relaying, re-direction, or multicasting mechanisms.

The protocols designed to support these operations may include optional fields and extensions to facilitate relaying, re-direction, or multicasting between DPV servers. However, it is not expected that DPV clients will support these features. If a protocol incorporates such functionalities, it must also provide mechanisms to ensure compatibility with DPV clients and servers that do not support these advanced features, ensuring adherence to the basic protocol requirements.

Security implications

The DPV protocol must incorporate mechanisms to prevent replay attacks, ensuring that malicious entities cannot reuse validation requests to gain unauthorized access. Importantly, this replay prevention must not depend on synchronized clocks between the client and server, which can be a vulnerability if clocks are not accurately aligned.[4]

When a certificate is validated successfully according to the specified policy, the DPV server should include this information in the response if requested by the client. However, if the certificate is found to be invalid or if the server cannot determine its validity, the server may choose to omit this information to avoid unnecessary disclosure of potentially sensitive details.

The revocation status information used by the DPV server pertains to the validation time specified in the client's request. This validation time might differ from the actual time when the certificate's private key was used to sign a document or transaction. Therefore, the DPV client should adjust the validation time to account for several delays:

By considering these factors, the DPV protocol try to ensure that the revocation status information accurately reflects the current validity of the certificate, enhancing the overall security and reliability of the validation process.

See also

References

  1. (September 2002), chapter 4, Delegated Path Validation and Delegated Path Discovery Protocol Requirements.
  2. (May 2008), chapter 6, Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile.
  3. Book: Ma . Zane . Austgen . James . Mason . Joshua . Durumeric . Zakir . Bailey . Michael . Tracing your roots: Exploring the TLS trust anchor ecosystem . 2021-11-02 . Proceedings of the 21st ACM Internet Measurement Conference . https://doi.org/10.1145/3487552.3487813 . IMC '21 . New York, NY, USA . Association for Computing Machinery . 179–194 . 10.1145/3487552.3487813 . 978-1-4503-9129-0.
  4. Book: Syverson, P. . A taxonomy of replay attacks [cryptographic protocols] . 1994 . Proceedings the Computer Security Foundations Workshop VII . https://ieeexplore.ieee.org/document/315935 . IEEE Comput. Soc. Press . 187–191 . 10.1109/CSFW.1994.315935 . 978-0-8186-6230-0.

Further reading

External links