You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Note that this is a sensitive TRC update, as the
certificate related to the compromised private key MUST be
replaced with an entirely new certificate (and not just changed).
This is not exactly true. If only the public key changes, and all other parameters are the same, It is a regular update AFAIK.
A trust reset is only required in the case the number of
compromised keys at the same time is greater or equal than the
TRC's quorum (see Section 3.1.2.2.7).
and a invalid update has been produced and distributed in the network. I think if the compromise is noticed early enough and an Update is issued and distributed in the network, then there is nothing an attacker can do anymore. Nodes in the SCION network store all the TRCs they have seen, and history cannot be rewriten.
Points to be reviewed:
5.
Security Considerations1.4.2.
Substitutes to Certificate RevocationLinks:
The text was updated successfully, but these errors were encountered: