首页> 外文会议>International Conference on Availability, Reliability and Security >Laribus: Privacy-Preserving Detection of Fake SSL Certificates with a Social P2P Notary Network
【24h】

Laribus: Privacy-Preserving Detection of Fake SSL Certificates with a Social P2P Notary Network

机译:Laribus:使用社交P2P公证网络保护假SSL证书的隐私保护检测

获取原文

摘要

In this paper we present Laribus, a peer-to-peer network designed to detect local man-in-the-middle attacks against SSL/TLS. With Laribus clients can validate the authenticity of a certificate presented to them by retrieving it from different vantage points on the network. Unlike previous solutions, clients do not have to trust a central notary service, nor do they have to rely on the cooperation of website owners. The Laribus network is based on a Social Network graph, which allows users to form Notary Groups that improve both privacy and availability. It integrates several well-known techniques, such as secret sharing, ring signatures, layered encryption, range queries and a Distributed Hash Table (DHT), to achieve privacy-aware queries, scalability and decentralization. We present the design and core components of Laribus, discuss its security properties and also provide results from a simulation-based feasibility study.
机译:在本文中,我们介绍了Laribus,这是一种对等网络,旨在检测针对SSL / TLS的本地中间人攻击。使用Laribus,客户可以通过从网络上的不同有利位置检索证书来验证提供给他们的证书的真实性。与以前的解决方案不同,客户不必信任中央公证服务,也不必依靠网站所有者的合作。 Laribus网络基于“社交网络”图,该图允许用户形成公证人组,从而改善隐私和可用性。它集成了多种众所周知的技术,例如秘密共享,环签名,分层加密,范围查询和分布式哈希表(DHT),以实现感知隐私的查询,可伸缩性和分散性。我们介绍了Laribus的设计和核心组件,讨论了其安全性,还提供了基于模拟的可行性研究的结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号