首页> 外文会议>International Conference on Telecommunications >Illuminate the Shadow: A Comprehensive Study of TLS Client Certificate Ecosystem in the Wild
【24h】

Illuminate the Shadow: A Comprehensive Study of TLS Client Certificate Ecosystem in the Wild

机译:照亮阴影:野外TLS客户证书生态系统的全面研究

获取原文

摘要

Client certificate authentication (CCA) is gaining greater significance, as more and more security-critical private activities such like e-bank and e-health are being conducted online, posing strong needs for mutual authentication. Unlike server certificates, active measurement of client certificates via probing techniques is infeasible since CCA is non-mandatory in the TLS protocol. Passive measurement is technically feasible but requires consistent access to large-scale Internet traffic to be comprehensive and convincing, which puts very high requirements on the research conditions. In this paper, we present a comprehensive study of the client certificate ecosystem, as the outcome of by far the largest passive measurement of client certificates in literature. As many as 97 million unique client certificates have been collected from the top-level academic network in China during six months. We analyze the actual use of CCA and classify the client certificates into three categories according to purposes: device authentication, user authentication, and application authentication. We discuss the security of client certificates with respect to the certificate attributes and make comparisons between client and server certificates. We also evaluate the risk of privacy leakage caused by client certificates, indicating the severity and the culprit. We hope our work would benefit the community by depicting an intuitive overview of the client certificate ecosystem and inspiring new thoughts on certificate usage in all kinds of scenarios.
机译:客户证书身份验证(CCA)正在增加重要意义,因为在网上进行E-Bank和电子健康等越来越多的安全性私人活动,因此对相互认证的强烈需求构成。与服务器证书不同,由于CCA在TLS协议中是非强制性的,因此通过探测技术的主服务测量是不可行的。被动测量在技术上是可行的,但需要一致地访问大规模的互联网流量,以全面和令人信服,这对研究条件提出了非常高的要求。在本文中,我们对客户证书生态系统进行了全面的研究,作为迄今为止在文献中最大的客户证书的被动测量的结果。在六个月内从中国的顶级学术网络收集了多达9700万个独特的客户证书。我们分析了CCA的实际使用,并根据目的将客户证书分为三类:设备认证,用户身份验证和应用程序身份验证。我们讨论了客户端证书对证书属性的安全性,并在客户端和服务器证书之间进行比较。我们还评估客户证书引起的隐私泄漏的风险,表明严重程度和罪魁祸首。我们希望我们的工作通过描绘客户证书生态系统的直观概述,并鼓励各种情况的证书使用的新思路。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号