...
首页> 外文期刊>ACM Transaction on Information and System Security >Server Location Verification (SLV) and Server Location Pinning: Augmenting TLS Authentication
【24h】

Server Location Verification (SLV) and Server Location Pinning: Augmenting TLS Authentication

机译:服务器位置验证(SLV)和服务器位置固定:增强TLS身份验证

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

We introduce the first known mechanism providing realtime server location verification. Its uses include enhancing server authentication by enabling browsers to automatically interpret server location information. We describe the design of this new measurement-based technique, Server Location Verification (SLV), and evaluate it using PlanetLab. We explain how SLV is compatible with the increasing trends of geographically distributed content dissemination over the Internet, without causing any new interoperability conflicts. Additionally, we introduce the notion of (verifiable) server location pinning (conceptually similar to certificate pinning) to support SLV, and evaluate their combined impact using a server-authentication evaluation framework. The results affirm the addition of new security benefits to the existing TLS-based authentication mechanisms. We implement SLV through a location verification service, the simplest version of which requires no server-side changes. We also implement a simple browser extension that interacts seamlessly with the verification infrastructure to obtain realtime server location-verification results.
机译:我们介绍了第一个提供实时服务器位置验证的已知机制。它的用途包括通过使浏览器自动解释服务器位置信息来增强服务器身份验证。我们将描述这种基于测量的新技术的服务器位置验证(SLV)的设计,并使用PlanetLab对其进行评估。我们将说明SLV如何与Internet上地理分布的内容分发的不断增长的趋势兼容,而不会引起任何新的互操作性冲突。此外,我们引入了(可验证的)服务器位置固定(概念上类似于证书固定)概念来支持SLV,并使用服务器身份验证评估框架评估它们的综合影响。结果证实,现有的基于TLS的身份验证机制增加了新的安全优势。我们通过位置验证服务实现SLV,该服务的最简单版本不需要服务器端更改。我们还实现了一个简单的浏览器扩展程序,该扩展程序可与验证基础结构无缝交互以获取实时服务器位置验证结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号