Laribus: privacy-preserving detection of fake SSL certificates with a social P2P notary network

Laribus: privacy-preserving detection of fake SSL certificates with a social P2P notary network
复制标题

Laribus:通过社交 P2P 公证网络对虚假 SSL 证书进行隐私保护检测

DOI:
--
复制
发表时间:
2013
期刊:
ARES
影响因子:
--
通讯作者:
H. Federrath
H. Federrath
中科院分区:
--
文献类型:
--
作者:
Karl;Dominik Herrmann;Andrea Micheloni;H. Federrath

文献摘要

被引文献

相似文献

在本文中,我们提出了Laribus,一个对等网络,旨在检测本地的人在中间攻击安全套接字层/传输层安全(SSL/TLS)。使用Laribus,客户端可以通过从网络上的不同Vantage位置检索证书来验证证书的真实性。与以前的解决方案不同,客户不必信任中央公证服务,也不必依赖网站所有者的合作。Laribus网络基于社交网络图,允许用户组成公证组,以提高隐私和可用性。它集成了几种众所周知的技术,如秘密共享,环签名,分层加密,范围查询和分布式哈希表(DHT),以实现隐私感知查询,可扩展性和去中心化。我们提出了Laribus的设计和核心组件,讨论了其安全性能,并提供了基于仿真的可行性研究结果。
In this paper we present Laribus, a peer-to-peer network designed to detect local man-in-the-middle attacks against secure socket layer/transport layer security (SSL/TLS). With Laribus, clients can validate the authenticity of a certificate presented to them by retrieving it from different vantage points on the network. Unlike previous solutions, clients do not have to trust a central notary service nor do they have to rely on the cooperation of website owners. The Laribus network is based on a social network graph, which allows users to form notary groups that improve both privacy and availability. It integrates several well-known techniques, such as secret sharing, ring signatures, layered encryption, range queries, and a distributed hash table (DHT), to achieve privacy-aware queries, scalability, and decentralization. We present the design and core components of Laribus, discuss its security properties, and also provide results from a simulation-based feasibility study.