SoK: Delegation and Revocation, the Missing Links in the Web's Chain of Trust

被引:12
|
作者
Chuat, Laurent [1 ]
Abdou, AbdelRahman [2 ]
Sasse, Ralf [1 ]
Sprenger, Christoph [1 ]
Basin, David [1 ]
Perrig, Adrian [1 ]
机构
[1] Swiss Fed Inst Technol, Dept Comp Sci, Zurich, Switzerland
[2] Carleton Univ, Sch Comp Sci, Ottawa, ON, Canada
关键词
public-key infrastructure (PKI); digital certificate; delegation; revocation; proxy certificate; content-delivery network (CDN);
D O I
10.1109/EuroSP48549.2020.00046
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The ability to quickly revoke a compromised key is critical to the security of any public-key infrastructure. Regrettably, most traditional certificate revocation schemes suffer from latency, availability, or privacy problems. These problems are exacerbated by the lack of a native delegation mechanism in TLS, which increasingly leads domain owners to engage in dangerous practices such as sharing their private keys with third parties. We analyze solutions that address the longstanding delegation and revocation shortcomings of the web PKI, with a focus on approaches that directly affect the chain of trust (i.e., the X.509 certification path). For this purpose, we propose a 19-criteria framework for characterizing revocation and delegation schemes. We also show that combining short-lived delegated credentials or proxy certificates with an appropriate revocation system would solve several pressing problems.
引用
收藏
页码:624 / 638
页数:15
相关论文
共 50 条
  • [31] Neurodegeneration in Alzheimer’s disease and glaucoma: overlaps and missing links
    Sagnik Sen
    Rohit Saxena
    Manjari Tripathi
    Deepti Vibha
    Rebika Dhiman
    Eye, 2020, 34 : 1546 - 1553
  • [32] A Cross-Multi-Domain Trust Assessment Authority Delegation Method Based on Automotive Industry Chain
    Li, Binyong
    Deng, Liangming
    Zhang, Jie
    Deng, Xianhui
    CMC-COMPUTERS MATERIALS & CONTINUA, 2025, 82 (01): : 407 - 426
  • [33] ORGANIZATIONAL-BEHAVIOR IN 1970S - MISSING LINKS
    STUPAK, RJ
    BUREAUCRAT, 1976, 5 (03): : 335 - 339
  • [34] New links in the Union's institutional chain
    不详
    EUROPEAN LAW REVIEW, 2010, 35 (01) : 1 - 2
  • [35] New approach to Web service composition using trust chain model
    Gao, Hong-Hao
    Li, Ying
    Zhang, Yuan-Yuan
    Tongxin Xuebao/Journal on Communications, 2011, 32 (9 A): : 77 - 86
  • [36] Connecting the Dots: Livestock Animals as Missing Links in the Chain of Microplastic Contamination and Human Health
    Pause, Francesca Corte
    Urli, Susy
    Crociati, Martina
    Stradaioli, Giuseppe
    Baufeld, Anja
    ANIMALS, 2024, 14 (02):
  • [37] How to pay for Social Security's Missing Trust Fund?
    Munnell, Alicia H.
    Hou, Wenliang
    Sanzenbacher, Geoffrey T.
    JOURNAL OF PENSION ECONOMICS & FINANCE, 2022, 21 (03): : 344 - 358
  • [39] Internet - Ashland links to EPA's Web site
    Fairley, P
    CHEMICAL WEEK, 1997, 159 (27) : 10 - 10
  • [40] Migration and Emancipation in West Africa's Labour History: The Missing Links
    Rossi, Benedetta
    SLAVERY & ABOLITION, 2014, 35 (01) : 23 - 46