首页> 外文会议>International Conference on Financial Cryptography and Data Security >Blockchain-Based Certificate Transparency and Revocation Transparency
【24h】

Blockchain-Based Certificate Transparency and Revocation Transparency

机译:基于区块链的证书透明度和撤销透明度

获取原文

摘要

Traditional X.509 public key infrastructures (PKIs) depend on certification authorities (CAs) to sign certificates, used in SSL/TLS to authenticate web servers and establish secure channels. However, recent security incidents indicate that CAs may (be compromised to) sign fraudulent certificates. In this paper, we propose blockchain-based certificate transparency and revocation transparency. Our scheme is compatible with X.509 PKIs but significantly reinforces the security guarantees of a certificate. The CA-signed certificates and their revocation status information of an SSL/TLS web server are published by the subject (i.e., the web server) as a transaction, and miners of the community append it to the global certificate blockchain after verifying the transaction and mining a block. The certificate blockchain acts as append-only public logs to monitor CAs' certificate signing and revocation operations, and an SSL/TLS web server is granted with the cooperative control on its certificates to balance the absolute authority of CAs in traditional PKIs. We implement the prototype system with Firefox and Nginx, and the experimental results show that it introduces reasonable overheads.
机译:传统的X.509公钥基础架构(PKIS)依赖于认证机构(CAS)来签署证书,用于SSL / TLS以进行身份​​验证Web服务器并建立安全频道。但是,最近的安全事件表明CAS可能(受到妥协)签署欺诈性证书。在本文中,我们提出基于区块的证书透明度和撤销透明度。我们的计划与X.509 PKI兼容,但大大加强了证书的安全保障。 SSL / TLS Web服务器的CA签名证书及其撤销状态信息由主题(即,Web服务器)作为事务发布,并且在验证交易后,社区的矿工将其附加到全局证书区块链中挖掘一个街区。证书区块链作为仅附加的公共日志来监控CAS的证书签名和撤销操作,并且SSL / TLS Web服务器被授予其证书的合作控制,以平衡传统PKI中CAS的绝对权限。我们用Firefox和Nginx实现原型系统,实验结果表明它引入了合理的开销。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号