首页> 外文期刊>Journal of computer security >CA trust management for the Web PKI
【24h】

CA trust management for the Web PKI

机译:Web PKI的CA信任管理

获取原文
获取原文并翻译 | 示例
           

摘要

The steadily growing number of certification authorities (CAs) assigned to the Web Public Key Infrastructure (Web PKI) and trusted by current browsers imposes severe security issues. Apart from being impossible for relying entities to assess whom they actually trust, the current binary trust model implemented with the Web PKI makes each CA a single point of failure and creates an enormous attack surface. In this article, we present CA-TMS, a user-centric CA trust management system based on trust views. CA-TMS can be used by relying entities to individually reduce the attack surface. CA-TMS works by restricting the trust placed in CAs of the Web PKI to trusting in exactly those CAs actually required by a relying entity. This restriction is based on locally collected information and does not require the alteration of the existing Web PKI. CA-TMS is complemented by an optional reputation system that allows to utilize the knowledge of other entities while maintaining the minimal set of trusted CAs. Our evaluation of CA-TMS with real world data shows that an attack surface reduction by more than 95% is achievable.
机译:分配给Web公钥基础结构(Web PKI)并由当前浏览器信任的证书颁发机构(CA)的数量稳步增长,这带来了严重的安全问题。除了依赖实体无法评估他们实际信任的人之外,使用Web PKI实现的当前二进制信任模型使每个CA都成为单一故障点,并造成了巨大的攻击面。在本文中,我们介绍CA-TMS,这是一个基于用户信任的基于信任视图的CA信任管理系统。依赖实体可以使用CA-TMS单独减少攻击面。 CA-TMS通过将放置在Web PKI的CA中的信任限制为完全信任依赖实体实际需要的那些CA来工作。此限制基于本地收集的信息,不需要更改现有的Web PKI。 CA-TMS辅以可选的信誉系统,该信誉系统允许在维持最少数量的受信任CA的同时利用其他实体的知识。我们对具有真实世界数据的CA-TMS的评估表明,可以将攻击面减少95%以上。

著录项

  • 来源
    《Journal of computer security》 |2014年第6期|913-959|共47页
  • 作者单位

    Theoretical Computer Science, Cryptography and Computer Algebra, Technische Universitaet Darmstadt, Hochschulstrasse 10, 64289 Darmstadt, Germany;

    Telecooperation Lab, Technische Universitaet Darmstadt and CASED, Darmstadt, Germany;

    Secure Mobile Networking Lab, Technische Universitaet Darmstadt and CASED. Darmstadt. Germany;

    Theoretical Computer Science, Cryptography and Computer Algebra, Technische Universitaet Darmstadt, Darmstadt, Germany;

    Telecooperation Lab, Technische Universitaet Darmstadt and CASED, Darmstadt, Germany;

  • 收录信息 美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Trust view; CA trust management system; Web PKI; levels of trust; attack surface reduction;

    机译:信任视图;CA信任管理系统;Web PKI;信任等级;减少攻击面;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号