CA trust management for the Web PKI

被引:17
作者
Braun, Johannes [1 ]
Volk, Florian [2 ,3 ]
Classen, Jiska [3 ,4 ]
Johannes, Buchmann [1 ]
Muehlhaeuser, Max [2 ,3 ]
机构
[1] Tech Univ Darmstadt, Theoret Comp Sci Cryptog & Comp Algebra, Hochschulstr 10, D-64289 Darmstadt, Germany
[2] Tech Univ Darmstadt, Telecooperat Lab, Darmstadt, Germany
[3] CASED, Darmstadt, Germany
[4] Tech Univ Darmstadt, Secure Mobile Networking Lab, Darmstadt, Germany
关键词
Trust view; CA trust management system; Web PKI; levels of trust; attack surface reduction;
D O I
10.3233/JCS-140509
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The steadily growing number of certification authorities (CAs) assigned to the Web Public Key Infrastructure (Web PKI) and trusted by current browsers imposes severe security issues. Apart from being impossible for relying entities to assess whom they actually trust, the current binary trust model implemented with the Web PKI makes each CA a single point of failure and creates an enormous attack surface. In this article, we present CA-TMS, a user-centric CA trust management system based on trust views. CA-TMS can be used by relying entities to individually reduce the attack surface. CA-TMS works by restricting the trust placed in CAs of the Web PKI to trusting in exactly those CAs actually required by a relying entity. This restriction is based on locally collected information and does not require the alteration of the existing Web PKI. CA-TMS is complemented by an optional reputation system that allows to utilize the knowledge of other entities while maintaining the minimal set of trusted CAs. Our evaluation of CA-TMS with real world data shows that an attack surface reduction by more than 95% is achievable.
引用
收藏
页码:913 / 959
页数:47
相关论文
共 51 条
[1]  
[Anonymous], 2013, 6962 RFC
[2]   Decentralized trust management [J].
Blaze, M ;
Feigenbaum, J ;
Lacy, J .
1996 IEEE SYMPOSIUM ON SECURITY AND PRIVACY, PROCEEDINGS, 1996, :164-173
[3]  
BOEYEN S., 2008, RFC 5280
[4]  
Braun Johannes, 2014, Public Key Infrastructures, Services and Applications. 10th European Workshop, EuroPKI 2013, Revised Selected Papers: LNCS 8341, P134, DOI 10.1007/978-3-642-53997-8_9
[5]   The Potential of an Individualized Set of trusted CAs: Defending against CA Failures in the Web PKI [J].
Braun, Johannes ;
Rynkowski, Gregor .
2013 ASE/IEEE INTERNATIONAL CONFERENCE ON SOCIAL COMPUTING (SOCIALCOM), 2013, :600-605
[6]  
Burnett C., 2010, P 9 INT C AUTONOMOUS, P241, DOI DOI 10.1016/J.DSS.2005.05.019
[7]   Evaluating trust in a public key certification authority [J].
Chadwick, DW ;
Basden, A .
COMPUTERS & SECURITY, 2001, 20 (07) :592-611
[8]  
Choice W.T.H., 2013, SSL TLS POSTPRISM ER
[9]  
Deza MM, 2009, ENCY DISTANCES
[10]  
Dierks T., 2008, 5246 RFC