【24h】

BB-PKI: Blockchain-Based Public Key Infrastructure Certificate Management

机译:BB-PKI:基于区块链的公钥基础架构证书管理

获取原文

摘要

Recently, real-world attacks against the web Public Key Infrastructure (PKI) have arisen more frequently. The current PKI that use Registration Authorities/Certificate Authorities (RAs/CAs) model suffer from notorious security vulnerabilities. Most of these vulnerabilities are due to compromises of RAs, which lead to impersonation attacks resulting in CAs misbehaving to issue bogus certificates. To counter this problem, many approaches, such as Certificate Transparency (CT), ARPKI, and PoliCert, have been proposed. Nonetheless, no solution has yet gained widespread acceptance as a result of complexity and deployability issues. Moreover, existing approaches still require to satisfy complicated interactions and synchronisation among the entities that are involved during certificate issuance, updates, and revocations. In this paper, we propose a new Blockchain-Based PKI (BB-PKI) to address these vulnerabilities of CA misbehaviour caused by impersonation attacks against RAs. Certificate Issuance Request (CIR) should be vouched by manifold RAs. Multiple CAs shall sign and issue the certificate using an out-of-band secure communication channel. Any RA that contributes to the verification process of a user’s request can publish the certificate in the blockchain by creating a smart contract certificate transaction. BB-PKI offers strong security guarantees, compromising $n - 1$ of the RAs or CAs is not enough to launch impersonation attacks, meaning that attackers cannot compromise more than the threshold of the latter signatures to launch an attack.
机译:最近,对Web公钥基础设施(PKI)的真实攻击更频繁地出现。使用注册权限/证书颁发机构(RAS / CAS)模型的目前的PKI遭受了臭名昭着的安全漏洞。这些漏洞中的大多数是由于RAS的妥协,这导致冒充攻击导致CAS行为不端发放虚假证书。为了解决这个问题,已经提出了许多方法,例如证书透明度(CT),ARPKI和Policert。尽管如此,由于复杂性和部署性问题,没有解决方案尚未获得广泛的接受。此外,现有方法仍然需要满足证书颁发,更新和撤销期间涉及的实体的复杂交互和同步。在本文中,我们提出了一种新的基于区块链的PKI(BB-PKI),以解决因对RAS的模拟攻击而引起的CA不当行为的脆弱性。证书签发请求(CIR)应由歧管RAS保证。多个CA应使用带外安全通信通道签署并发出证书。有助于用户请求的验证过程的任何RA可以通过创建智能合同证书事务来发布区块链中的证书。 BB-PKI提供强烈的安全保证,损害$ N - 1 $的RAS或CA不足以启动冒充攻击,这意味着攻击者无法损害后者签名的阈值以发动攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号