Arpki: Attack Resilient Public-Key Infrastructure

CCS(2014)

引用 170|浏览204
暂无评分
摘要
We present ARPKI, a public-key infrastructure that ensures that certificate-related operations, such as certificate issuance, update, revocation, and validation, are transparent and accountable. ARPKI is the first such infrastructure that systematically takes into account requirements identified by previous research. Moreover, ARPKI is co-designed with a formal model, and we verify its core security property using the TAMARIN prover. We present a proof-of-concept implementation providing all features required for deployment. ARPKI efficiently handles the certification process with low overhead and without incurring additional latency to TLS.ARPKI offers extremely strong security guarantees, where compromising n - 1 trusted signing and verifying entities is insufficient to launch an impersonation attack. Moreover, it deters misbehavior as all its operations are publicly visible.
更多
查看译文
关键词
Public-Key Infrastructure,TLS,certificate validation,public log servers,formal validation,attack resilience
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要