X.509 Check: A Tool to Check the Safety and Security of Digital Certificates

被引:2
作者
Alrawais, Arwa [1 ,2 ]
Alhothaily, Abdulrahman [1 ,3 ]
Cheng, Xiuzhen [1 ]
机构
[1] George Washington Univ, Dept Comp Sci, Washington, DC 20052 USA
[2] Prince Sattam Bin Abdulaziz Univ, Coll Comp Engn & Sci, Al Kharj, Saudi Arabia
[3] Saudi Arabian Monetary Agcy, Gen Dept Payment Syst, Riyadh, Saudi Arabia
来源
2015 INTERNATIONAL CONFERENCE ON IDENTIFICATION, INFORMATION, AND KNOWLEDGE IN THE INTERNET OF THINGS (IIKI) | 2015年
关键词
Network security; PKI; X.509 digital certificate;
D O I
10.1109/IIKI.2015.36
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Digital certificates, the primary mechanism for providing secure communications in the Internet, have been widely deployed. In this paper, we propose X.509 Check, a tool designed to analyze the security properties and the quality of digital certificates. X.509 Check can be used to verify digital certificates and provide a deep analysis on the quality and configuration of any digital certificate using more than 30 security features. It can be useful for auditors, system administrators, and security officers. This paper aims to create a straightforward evaluation approach, allowing auditors and administrators to use the X.509 Check tool to examine any digital certificate without the need to become X.509 standard experts. We also report our findings of using this tool to check against one hundred X.509 digital certificates. Our results reveal the existence of many issues and problems that could lead to serious security risks.
引用
收藏
页码:130 / 133
页数:4
相关论文
共 13 条
[1]  
[Anonymous], 2003, Understanding PKI: concepts, standards, and deployment considerations
[2]  
[Anonymous], 2015, CERT AUTH TRUST MOD
[3]  
Bauer C., 2012, IEEE International Conference on Communications (ICC 2012), P6727, DOI 10.1109/ICC.2012.6364723
[4]  
Cooper David, 2008, Technical Report.
[5]  
Durumeric Z., 2013, Proc. of IMC '13, DOI 10.1145/2504730.2504755
[6]  
Ellison C., 2000, Computer Security Journal, V16, P1
[7]   Generalized Digital Certificate for User Authentication and Key Establishment for Secure Communications [J].
Harn, Lein ;
Ren, Jian .
IEEE TRANSACTIONS ON WIRELESS COMMUNICATIONS, 2011, 10 (07) :2372-2379
[8]  
Keith A., 2003, TECHNICAL REPORT
[9]  
Martin J., 2014, 5 SERIOUS PROBLEMS H
[10]  
Matsumoto S., 2015, P NDSS WORKSH SEC EM