SoK: Delegation and Revocation, the Missing Links in the Web's Chain of Trust

被引:12
|
作者
Chuat, Laurent [1 ]
Abdou, AbdelRahman [2 ]
Sasse, Ralf [1 ]
Sprenger, Christoph [1 ]
Basin, David [1 ]
Perrig, Adrian [1 ]
机构
[1] Swiss Fed Inst Technol, Dept Comp Sci, Zurich, Switzerland
[2] Carleton Univ, Sch Comp Sci, Ottawa, ON, Canada
关键词
public-key infrastructure (PKI); digital certificate; delegation; revocation; proxy certificate; content-delivery network (CDN);
D O I
10.1109/EuroSP48549.2020.00046
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The ability to quickly revoke a compromised key is critical to the security of any public-key infrastructure. Regrettably, most traditional certificate revocation schemes suffer from latency, availability, or privacy problems. These problems are exacerbated by the lack of a native delegation mechanism in TLS, which increasingly leads domain owners to engage in dangerous practices such as sharing their private keys with third parties. We analyze solutions that address the longstanding delegation and revocation shortcomings of the web PKI, with a focus on approaches that directly affect the chain of trust (i.e., the X.509 certification path). For this purpose, we propose a 19-criteria framework for characterizing revocation and delegation schemes. We also show that combining short-lived delegated credentials or proxy certificates with an appropriate revocation system would solve several pressing problems.
引用
收藏
页码:624 / 638
页数:15
相关论文
共 50 条
  • [21] Communication and the laying on of hands - medicine's missing links
    Ncayiyana, Daniel J.
    SAMJ SOUTH AFRICAN MEDICAL JOURNAL, 2006, 96 (11): : 1135 - 1135
  • [22] The Care Chain's Broken Links
    Quart, Alissa
    NATION, 2014, 298 (20) : 18 - 21
  • [23] Shattered Chain of Trust: Understanding Security Risks in Cross-Cloud IoT Access Delegation
    Yuan, Bin
    Jia, Yan
    Xing, Luyi
    Zhao, Dongfang
    Wang, XiaoFeng
    Zou, Deqing
    Jin, Hai
    Zhang, Yuqing
    PROCEEDINGS OF THE 29TH USENIX SECURITY SYMPOSIUM, 2020, : 1183 - 1200
  • [24] Certificate chain discovery in web of trust for ad hoc networks
    Mohri, Hisashi
    Yasuda, Ikuya
    Takata, Yoshiaki
    Seki, Hiroyuki
    21ST INTERNATIONAL CONFERENCE ON ADVANCED NETWORKING AND APPLICATIONS WORKSHOPS/SYMPOSIA, VOL 2, PROCEEDINGS, 2007, : 479 - +
  • [25] Genotyping of Mycobacterium tuberculosis in China and Missing Links in the Chain of Ongoing Transmission of Tuberculosis
    Arend, Sandra M.
    van Soolingen, Dick
    CLINICAL INFECTIOUS DISEASES, 2015, 61 (02) : 228 - 232
  • [26] WEB TRUST - A MODERATOR OF THE WEB'S PERCEIVED INDIVIDUAL IMPACT
    Riemenschneider, Cynthia K.
    Jones, Kiku
    Leonard, Lori N. K.
    JOURNAL OF COMPUTER INFORMATION SYSTEMS, 2009, 49 (04) : 10 - 18
  • [27] Will hypertext become the Web's missing link?
    Bieber, M
    Hall, W
    Marshall, C
    Retallack, DS
    Vercoustre, AM
    White, B
    COMPUTER NETWORKS AND ISDN SYSTEMS, 1998, 30 (1-7): : 754 - 756
  • [28] Neurodegeneration in Alzheimer's disease and glaucoma: overlaps and missing links
    Sen, Sagnik
    Saxena, Rohit
    Tripathi, Manjari
    Vibha, Deepti
    Dhiman, Rebika
    EYE, 2020, 34 (09) : 1546 - 1553
  • [29] Missing links: the traces of history in Chantal Akerman's cinema
    Leandro, Anita
    STUDIES IN FRENCH CINEMA, 2018, 18 (03): : 208 - 222
  • [30] CHINA'S ANTISHIP BALLISTIC MISSILE Developments and Missing Links
    Hagt, Eric
    Durnin, Matthew
    NAVAL WAR COLLEGE REVIEW, 2009, 62 (04) : 87 - 115