CAPS: Smoothly Transitioning to a More Resilient Web PKI

CAPS: Smoothly Transitioning to a More Resilient Web PKI
复制标题

CAPS:平稳过渡到更具弹性的 Web PKI

DOI:
10.1145/3427228.3427284
复制
发表时间:
2020
期刊:
Annual Computer Security Applications Conference
影响因子:
--
通讯作者:
Parno, Bryan
Parno, Bryan
中科院分区:
--
文献类型:
--
作者:
Matsumoto, Stephanos;Bosamiya, Jay;Dai, Yucheng;van Oorschot, Paul;Parno, Bryan

文献摘要

参考文献

相似文献

最近提出的许多建议,以提高弹性的Web PKI对行为不端的CA面临重大障碍的部署。这些障碍包括:(1)需要对现有PKI参与者及其交互进行重大更改,(2)缺乏防止降级攻击的信令机制,(3)缺乏增量部署策略,以及(4)使用不灵活的机制,阻碍从错误配置或私钥丢失或泄露中恢复。因此,这些建议很少被广泛部署,尽管它们承诺更安全的Web PKI。为了解决这些障碍,我们提出了自动策略和信令(CAPS),一个系统,利用现有的Web PKI的基础设施,以克服上述障碍的证书。CAPS提供了一个无缝和安全的过渡,从今天的不安全的Web PKI和目前和未来的建议,以改善Web PKI。至关重要的是,使用CAPS,域可以在存在一个或多个行为不端的CA时采取简单的步骤来保护自己免受MITM攻击,而域和CA之间的交互基本上保持不变。我们实现了CAPS,并表明它增加了最多5%的连接建立延迟。
Many recent proposals to increase the resilience of the Web PKI against misbehaving CAs face significant obstacles to deployment. These hurdles include (1) the requirement of drastic changes to the existing PKI players and their interactions, (2) the lack of signaling mechanisms to protect against downgrade attacks, (3) the lack of an incremental deployment strategy, and (4) the use of inflexible mechanisms that hinder recovery from misconfiguration or from the loss or compromise of private keys. As a result, few of these proposals have seen widespread deployment, despite their promise of a more secure Web PKI. To address these roadblocks, we propose Certificates with Automated Policies and Signaling (CAPS), a system that leverages the infrastructure of the existing Web PKI to overcome the aforementioned hurdles. CAPS offers a seamless and secure transition away from today’s insecure Web PKI and towards present and future proposals to improve the Web PKI. Crucially, with CAPS, domains can take simple steps to protect themselves from MITM attacks in the presence of one or more misbehaving CAs, and yet the interaction between domains and CAs remains fundamentally the same. We implement CAPS and show that it adds at most 5% to connection establishment latency.
DOI: 10.1093/comjnl/bxw039
发表时间: 2014-08
期刊: ArXiv
影响因子: --
作者:
Jiangshan Yu;Vincent Cheval;M. Ryan
通讯作者: Jiangshan Yu;Vincent Cheval;M. Ryan
DOI: 10.1162/089120100561601
发表时间: 2000-03-01
影响因子: 9.3
作者:
Daciuk, J;Mihov, S;Watson, RE
通讯作者: Watson, RE
负责任的密钥基础设施(AKI):公钥验证基础设施的提案
DOI: --
发表时间: 2013
期刊: The Web Conference
影响因子: --
作者:
T. Kim;Lin;A. Perrig;Collin Jackson;Virgil D. Gligor
通讯作者: Virgil D. Gligor
有限状态自动机的较小表示
DOI: --
发表时间: 2011
影响因子: 1.1
作者:
J. Daciuk;Dawid Weiss
通讯作者: Dawid Weiss
HTTP/2 中的辅助证书身份验证
DOI: --
发表时间: 2017
期刊:
影响因子: --
作者:
M. Bishop;M. Thomson;N. Sullivan
通讯作者: N. Sullivan