【24h】

Improving Robustness of PGP Keyrings by Conflict Detection

机译:通过冲突检测提高PGP密钥环的鲁棒性

获取原文
获取原文并翻译 | 示例

摘要

Secure authentication frequently depends on the correct recognition of a user's public key. When there is no certificate authority, this key is obtained from other users using a web of trust. If users can be malicious, trusting the key information they provide is risky. Previous work has suggested the use of redundancy to improve the trustworthiness of user-provided key information. In this paper, we address two issues not previously considered. First, we solve the problem of users who claim multiple, false identities, or who possess multiple keys. Secondly, we show that conflicting certificate information can be exploited to improve trustworthiness. Our methods are demonstrated on both real and synthetic PGP keyrings, and their performance is discussed.
机译:安全身份验证通常取决于对用户公钥的正确识别。如果没有证书颁发机构,则使用信任网络从其他用户获取此密钥。如果用户可能是恶意的,则信任他们提供的关键信息是有风险的。先前的工作建议使用冗余来提高用户提供的关键信息的可信度。在本文中,我们解决了先前未考虑的两个问题。首先,我们解决了声称拥有多个错误身份或拥有多个密钥的用户的问题。其次,我们证明可以利用有冲突的证书信息来提高可信度。我们的方法已在实际PGP密钥环和合成PGP密钥环上进行了演示,并讨论了它们的性能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号