SoK: Delegation and Revocation, the Missing Links in the Web's Chain of Trust

2020 IEEE European Symposium on Security and Privacy (EuroS&P)(2020)

引用 22|浏览53
暂无评分
摘要
The ability to quickly revoke a compromised key is critical to the security of any public-key infrastructure. Regrettably, most traditional certificate revocation schemes suffer from latency, availability, or privacy problems. These problems are exacerbated by the lack of a native delegation mechanism in TLS, which increasingly leads domain owners to engage in dangerous practices such as sharing their private keys with third parties. We analyze solutions that address the longstanding delegation and revocation shortcomings of the web PKI, with a focus on approaches that directly affect the chain of trust (i.e., the X.509 certification path). For this purpose, we propose a 19-criteria framework for characterizing revocation and delegation schemes. We also show that combining short-lived delegated credentials or proxy certificates with an appropriate revocation system would solve several pressing problems.
更多
查看译文
关键词
public-key infrastructure (PKI),digital certificate,delegation,revocation,proxy certificate,content-delivery network (CDN)
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要