首页> 外文会议>International Conference on Information Technology - New Generations >A Novel Regular Format for X.509 Digital Certificates
【24h】

A Novel Regular Format for X.509 Digital Certificates

机译:X.509数字证书的新颖常规格式

获取原文

摘要

Digital certificates are one of the key components to ensure secure network communications. The complexity of the certificate standard, ITU-R-X.509, has led to a number of breaches in the TLS protocol security due to certificate misinterpretation by TLS libraries. We argue that the root cause of such an issue is the complexity of the certificate structure, which can be gauged with the framework of formal language theory: the language describing digital certificates is context sensitive. Such a complexity led to handcrafted X.509 parsers, resulting in implementations which are not guaranteed to perform correct language recognition. We highlight the issues in X.509, and propose a new format for digital certificates, designed to be parsed effectively and efficiently, while retaining the same semantic expressiveness. The certificate format can be deployed gradually, is fully specified as a regular language, and is specified as a formal grammar from which a provably correct parser can be automatically derived. We validate the effectiveness of our proposal, and the linear running time provided by the approach, generating an instance of the parser with a production grade lexer/parser generation framework.
机译:数字证书是确保安全网络通信的关键组件之一。 ITU-R-X.509证书标准的复杂性导致TLS协议安全性的许多泄露因TLS库的证书误解而导致TLS协议安全性。我们认为这种问题的根本原因是证书结构的复杂性,可以用正式语言理论的框架衡量:描述数字证书的语言是上下文敏感的。这种复杂性导致手工制作的X.509解析器,导致实现的实现,不保证执行正确的语言识别。我们突出显示X.509中的问题,并为数字证书提出了一种新格式,旨在有效且有效地解析,同时保持相同的语义表达。证书格式可以逐渐部署,完全指定为常规语言,并被指定为正式的语法可以自动派生可怕的正确解析器。我们验证了我们提案的有效性,以及该方法提供的线性运行时间,用生产等级Lexer /解析器生成框架生成解析器的实例。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号