SoK: Delegation and Revocation, the Missing Links in the Web's Chain of Trust

被引:12
|
作者
Chuat, Laurent [1 ]
Abdou, AbdelRahman [2 ]
Sasse, Ralf [1 ]
Sprenger, Christoph [1 ]
Basin, David [1 ]
Perrig, Adrian [1 ]
机构
[1] Swiss Fed Inst Technol, Dept Comp Sci, Zurich, Switzerland
[2] Carleton Univ, Sch Comp Sci, Ottawa, ON, Canada
关键词
public-key infrastructure (PKI); digital certificate; delegation; revocation; proxy certificate; content-delivery network (CDN);
D O I
10.1109/EuroSP48549.2020.00046
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The ability to quickly revoke a compromised key is critical to the security of any public-key infrastructure. Regrettably, most traditional certificate revocation schemes suffer from latency, availability, or privacy problems. These problems are exacerbated by the lack of a native delegation mechanism in TLS, which increasingly leads domain owners to engage in dangerous practices such as sharing their private keys with third parties. We analyze solutions that address the longstanding delegation and revocation shortcomings of the web PKI, with a focus on approaches that directly affect the chain of trust (i.e., the X.509 certification path). For this purpose, we propose a 19-criteria framework for characterizing revocation and delegation schemes. We also show that combining short-lived delegated credentials or proxy certificates with an appropriate revocation system would solve several pressing problems.
引用
收藏
页码:624 / 638
页数:15
相关论文
共 50 条
  • [41] MISSING LINKS IN THE PRESIDENT'S EVOLUTION ON SAME-SEX MARRIAGE
    Prakash, Saikrishna Bangalore
    FORDHAM LAW REVIEW, 2012, 81 (02) : 553 - 575
  • [42] Firing the Canon: The Historical Search for Literary Journalism's Missing Links
    Roberts, Nancy L.
    LITERARY JOURNALISM STUDIES, 2012, 4 (02): : 81 - 93
  • [43] Missing links in the regulatory chain controlling life cycle emissions of hazardous chemicals from articles
    Molander, L.
    Breitholtz, M.
    Ruden, C.
    TOXICOLOGY LETTERS, 2011, 205 : S243 - S243
  • [45] The Chain of Implicit Trust: An Analysis of the Web Third-party Resources Loading
    Ikram, Muhammad
    Masood, Rahat
    Tyson, Gareth
    Kaafar, Mohamed Ali
    Loizon, Noha
    Ensafi, Roya
    WEB CONFERENCE 2019: PROCEEDINGS OF THE WORLD WIDE WEB CONFERENCE (WWW 2019), 2019, : 2851 - 2857
  • [46] Trust, power and supply chain integration in Web-enabled supply chains
    Mora-Monge, Carlo
    Quesada, Gioconda
    Gonzalez, Marvin E.
    Davis, Joshua M.
    SUPPLY CHAIN MANAGEMENT-AN INTERNATIONAL JOURNAL, 2019, 24 (04) : 524 - 539
  • [47] Variable and complex food web structures revealed by exploring missing trophic links between birds and biofilm
    Kuwae, Tomohiro
    Miyoshi, Eiichi
    Hosokawa, Shinya
    Ichimi, Kazuhiko
    Hosoya, Jun
    Amano, Tatsuya
    Moriya, Toshifumi
    Kondoh, Michio
    Ydenberg, Ronald C.
    Elner, Robert W.
    ECOLOGY LETTERS, 2012, 15 (04) : 347 - 356
  • [48] Bielastic web of links: A discrete model of Csonka's beam
    Nemeth, Robert K.
    Kocsis, Attila
    INTERNATIONAL JOURNAL OF NON-LINEAR MECHANICS, 2014, 63 : 49 - 59
  • [49] Women's Participation in Domestic Duties and Paid Employment in India: The Missing Links
    Samantroy, Ellina
    INDIAN JOURNAL OF LABOUR ECONOMICS, 2020, 63 (02): : 437 - 457
  • [50] Legal systems, decisionmaking, and the science of Earth's systems: Procedural missing links
    Robinson, NA
    ECOLOGY LAW QUARTERLY, 2001, 27 (04) : 1077 - 1161