首页> 外文会议>IEEE Symposium on Security and Privacy >IKP: Turning a PKI Around with Decentralized Automated Incentives
【24h】

IKP: Turning a PKI Around with Decentralized Automated Incentives

机译:IKP:通过分散的自动激励机制扭转PKI的局面

获取原文

摘要

Despite a great deal of work to improve the TLS PKI, CA misbehavior continues to occur, resulting in unauthorized certificates that can be used to mount man-in-the-middle attacks against HTTPS sites. CAs lack the incentives to invest in higher security, and the manual effort required to report a rogue certificate deters many from contributing to the security of the TLS PKI. In this paper, we present IKP, a platform that automates responses to unauthorized certificates and provides incentives for CAs to behave correctly and for others to report potentially unauthorized certificates. Domains in IKP specify criteria for their certificates, and CAs specify reactions such as financial penalties that execute in case of unauthorized certificate issuance. By leveraging smart contracts and blockchain-based consensus, we can decentralize IKP while still providing automated incentives. We describe a theoretical model for payment flows and implement IKP in Ethereum to show that decentralizing and automating PKIs with financial incentives is both economically sound and technically viable.
机译:尽管为改善TLS PKI进行了大量工作,但CA仍在继续发生不当行为,从而导致未经授权的证书可用于对HTTPS站点发起中间人攻击。 CA缺乏投资于更高安全性的动机,并且报告恶意证书所需的手动工作阻止了许多人为TLS PKI的安全性做出贡献。在本文中,我们介绍了IKP,该平台可自动执行对未授权证书的响应,并激励CA正确行为,并鼓励其他机构报告潜在的未授权证书。 IKP中的域指定其证书的标准,而CA指定在未授权证书颁发的情况下执行的反应,例如罚款。通过利用智能合约和基于区块链的共识,我们可以分散IKP的权力,同时仍然提供自动激励措施。我们描述了一种支付流的理论模型,并在以太坊中实施了IKP,以证明通过财政激励使PKI分散和自动化在经济上和技术上都是可行的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号