首页> 外文期刊>EURASIP journal on information security >Laribus: privacy-preserving detection of fake SSL certificates with a social P2P notary network
【24h】

Laribus: privacy-preserving detection of fake SSL certificates with a social P2P notary network

机译:Lasibus:通过社会P2P公证网络保护伪证SSL证书的隐私检测

获取原文
           

摘要

In this paper we present Laribus, a peer-to-peer network designed to detect local man-in-the-middle attacks against secure socket layer/transport layer security (SSL/TLS). With Laribus, clients can validate the authenticity of a certificate presented to them by retrieving it from different vantage points on the network. Unlike previous solutions, clients do not have to trust a central notary service nor do they have to rely on the cooperation of website owners. The Laribus network is based on a social network graph, which allows users to form notary groups that improve both privacy and availability. It integrates several well-known techniques, such as secret sharing, ring signatures, layered encryption, range queries, and a distributed hash table (DHT), to achieve privacy-aware queries, scalability, and decentralization. We present the design and core components of Laribus, discuss its security properties, and also provide results from a simulation-based feasibility study.
机译:在本文中,我们展示了Lasibus,一个对等网络,旨在检测局部内部攻击的局部攻击,针对安全套接字层/传输层安全性(SSL / TLS)。使用Laribus,客户端可以通过从网络上的不同Vantage点检索它来验证给它们的证书的真实性。与以前的解决方案不同,客户不必信任核心公证服务,也不得不依赖网站所有者的合作。 Laribus网络基于社交网络图形,允许用户形成提高隐私和可用性的公证组。它集成了几种众所周知的技术,例如秘密共享,环形签名,分层加密,范围查询和分布式哈希表(DHT),以实现隐私感知查询,可扩展性和分散化。我们介绍了Laribus的设计和核心组件,讨论其安全性质,并提供基于模拟的可行性研究的结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号