DTKI: A New Formalized PKI with Verifiable Trusted Parties

DTKI: A New Formalized PKI with Verifiable Trusted Parties
复制标题

DOI:
10.1093/comjnl/bxw039
复制
发表时间:
2014-08
期刊:
ArXiv
影响因子:
--
通讯作者:
Jiangshan Yu;Vincent Cheval;M. Ryan
Jiangshan Yu;Vincent Cheval;M. Ryan
中科院分区:
其他
文献类型:
--
作者:
Jiangshan Yu;Vincent Cheval;M. Ryan

文献摘要

被引文献

相似文献

基于web的应用程序的公钥验证协议的安全性最近引起了人们的关注,因为证书颁发模型存在弱点,以及随之而来的攻击。最近使用公共日志的建议已经成功地使证书管理更加透明和可验证。然而,这些提议涉及一套固定的权力。这意味着寡头垄断形成了。当前基于日志的系统的另一个问题是它们严重依赖于监视日志的可信方。我们提出了一种分布式透明密钥基础设施(DTKI),它大大减少了服务提供商的寡头垄断,并允许对受信任方的行为进行验证。此外,本文还形式化了公共日志数据结构,并对DTKI所保证的安全性进行了形式化分析。
The security of public key validation protocols for web-based applications has recently attracted attention because of weaknesses in the certificate authority model, and consequent attacks. Recent proposals using public logs have succeeded in making certificate management more transparent and verifiable. However, those proposals involve a fixed set of authorities. This means an oligopoly is created. Another problem with current log-based system is their heavy reliance on trusted parties that monitor the logs. We propose a distributed transparent key infrastructure (DTKI), which greatly reduces the oligopoly of service providers and allows verification of the behaviour of trusted parties. In addition, this paper formalises the public log data structure and provides a formal analysis of the security that DTKI guarantees.