Leveraging locality of reference for certificate revocation

Leveraging locality of reference for certificate revocation
复制标题

利用引用位置进行证书吊销

DOI:
10.1145/3359789.3359819
复制
发表时间:
2019
期刊:
ACSAC '19: Proceedings of the 35th Annual Computer Security Applications Conference
影响因子:
--
通讯作者:
Seamons, Kent
Seamons, Kent
中科院分区:
--
文献类型:
--
作者:
Dickinson, Luke;Smith, Trevor;Seamons, Kent

文献摘要

参考文献

被引文献

相似文献

X.509证书撤销可防御涉及受损证书的中间人攻击。随着HTTPS采用率的飙升,证书撤销策略面临可扩展性、有效性和部署挑战。我们提出了证书撤销表(CRT),一个新的撤销策略,具有竞争力或超过替代国家的最先进的解决方案的有效性,效率,证书增长的可扩展性,大规模撤销事件的可扩展性,撤销的及时性,隐私和部署要求。CRT设计假定引用位置适用于组织访问的证书。CRT定期检查组织最近使用的X.509证书的撤销状态。预先检查客户端可能使用的证书的撤销状态,避免了按需证书撤销检查的安全问题。为了验证我们的方法的有效性和效率,我们模拟了CRT使用60天的TLS流量日志从杨百翰大学测量主动刷新撤销状态信息的效果为不同的证书工作集窗口长度。45天的工作集窗口大小导致平均99.86%的TLS握手提前缓存了撤销信息。CRT存储要求很小。初始撤销状态信息需要下载6.7 MB的文件,后续更新每天只需要205.1 KB的带宽。仅包括已撤销证书的更新每天仅需要215字节的带宽。
X.509 certificate revocation defends against man-in-the-middle attacks involving a compromised certificate. Certificate revocation strategies face scalability, effectiveness, and deployment challenges as HTTPS adoption rates have soared. We propose Certificate Revocation Table (CRT), a new revocation strategy that is competitive with or exceeds alternative state-of-the-art solutions in effectiveness, efficiency, certificate growth scalability, mass revocation event scalability, revocation timeliness, privacy, and deployment requirements. The CRT design assumes that locality of reference applies to the certificates accessed by an organization. The CRT periodically checks the revocation status of X.509 certificates recently used by the organization. Pre-checking the revocation status of certificates the clients are likely to use avoids the security problems of on-demand certificate revocation checking.To validate both the effectiveness and efficiency of our approach, we simulated a CRT using 60 days of TLS traffic logs from Brigham Young University to measure the effects of actively refreshing revocation status information for various certificate working set window lengths. A working set window size of 45 days resulted in an average of 99.86% of the TLS handshakes having revocation information cached in advance. The CRT storage requirements are small. The initial revocation status information requires downloading a 6.7 MB file, and subsequent updates require only 205.1 KB of bandwidth daily. Updates that include only revoked certificates require just 215 bytes of bandwidth per day.
传输层安全 (TLS) 快速启动
DOI: --
发表时间: 2010
期刊:
影响因子: --
作者:
Adam Langley
通讯作者: Adam Langley
DOI: --
发表时间: 2016-10
期刊: --
影响因子: --
作者:
Mark O'Neill;S. Heidbrink;Scott Ruoti;Jordan Whitehead;Dan Bunker;Luke Dickinson;Travis Hendershot;J. Reynolds;K. Seamons;D. Zappala
通讯作者: Mark O'Neill;S. Heidbrink;Scott Ruoti;Jordan Whitehead;Dan Bunker;Luke Dickinson;Travis Hendershot;J. Reynolds;K. Seamons;D. Zappala
DOI: 10.17487/rfc7633
发表时间: 2015-10
期刊: RFC
影响因子: --
作者:
P. Hallam-Baker
通讯作者: P. Hallam-Baker
DOI: 10.1109/icdcs.2016.91
发表时间: 2016
期刊: 2016 IEEE 36th International Conference on Distributed Computing Systems (ICDCS)
影响因子: --
作者:
Pawel Szalachowski;L. Chuat;Taeho Lee;A. Perrig
通讯作者: A. Perrig
Web 浏览器进行 TLS 连接验证:为什么 Web 浏览器仍然不同意?
DOI: 10.1109/compsac.2017.240
发表时间: 2017
期刊: 2017 IEEE 41st Annual Computer Software and Applications Conference (COMPSAC)
影响因子: --
作者:
A. Wazan;R. Laborde;D. Chadwick;F. Barrère;A. Benzekri
通讯作者: A. Benzekri