The effect of a MANET proxy overlay for certificate validation services

Certificate validation based on PKIX protocols does not work well under the particular conditions found in a MANET: Episodic connectivity and low bandwidth. We propose an overlay network of validation proxy servers which exploit cooperative caching of recent validation results. The proxy overlay improves the availability of the validation service and reduces the network traffic. The design employs the XKMS certificate validation protocols and a cross-layer approach to the construction of the proxy overlay.