Towards Sustainable Evolution for the TLS Public-Key Infrastructure

被引:2
|
作者
Lee, Taeho [1 ]
Pappas, Christos [1 ]
Szalachowski, Pawel [2 ]
Perrig, Adrian [1 ]
机构
[1] Swiss Fed Inst Technol, Zurich, Switzerland
[2] SUTD, Singapore, Singapore
来源
PROCEEDINGS OF THE 2018 ACM ASIA CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (ASIACCS'18) | 2018年
基金
欧洲研究理事会;
关键词
D O I
10.1145/3196494.3196520
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Motivated by the weaknesses of today's TLS public-key infrastructure (PKI), recent studies have proposed numerous enhancements to fortify the PKI ecosystem. Deploying one particular enhancement is no panacea, since each one solves only a subset of the problems. At the same time, the high deployment barrier makes the benefit-cost ratio tilt in the wrong direction, leading to disappointing adoption rates for most proposals. As a way to escape from this conundrum, we propose a framework that supports the deployment of multiple PKI enhancements, with the ability to accommodate new, yet unforeseen, enhancements in the future. To enable mass adoption, we enlist the cloud as a "centralized" location where multiple enhancements can be accessed with high availability. Our approach is compatible with existing protocols and networking practices, with the ambition that a few changes will enable sustainable evolution for PKI enhancements. We provide extensive evaluation to show that the approach is scalable, cost-effective, and does not degrade communication performance. As a use case, we implement and evaluate two PKI enhancements.
引用
收藏
页码:637 / 649
页数:13
相关论文
共 50 条
  • [1] Modelling a public-key infrastructure
    Maurer, U.
    Lecture Notes in Computer Science, 1146
  • [2] Public-key infrastructure interoperation
    Ford, W
    1998 IEEE AEROSPACE CONFERENCE PROCEEDINGS, VOL 4, 1998, : 329 - 333
  • [3] BKI: Towards Accountable and Decentralized Public-Key Infrastructure with Blockchain
    Wan, Zhiguo
    Guan, Zhangshuang
    Zhuo, Feng
    Xian, Hequn
    SECURITY AND PRIVACY IN COMMUNICATION NETWORKS, SECURECOMM 2017, 2018, 238 : 644 - 658
  • [4] Towards a Smart Contract-Based, Decentralized, Public-Key Infrastructure
    Patsonakis, Christos
    Samari, Katerina
    Roussopoulos, Mema
    Kiayias, Aggelos
    CRYPTOLOGY AND NETWORK SECURITY (CANS 2017), 2018, 11261 : 299 - 321
  • [5] Accountable and Transparent TLS Certificate Management: An Alternate Public-Key Infrastructure with Verifiable Trusted Parties
    Khan, Salabat
    Zhang, Zijian
    Zhu, Liehuang
    Li, Meng
    Safi, Qamas Gul Khan
    Chen, Xiaobing
    SECURITY AND COMMUNICATION NETWORKS, 2018,
  • [6] TOWARD A NATIONAL PUBLIC-KEY INFRASTRUCTURE
    CHOKHANI, S
    IEEE COMMUNICATIONS MAGAZINE, 1994, 32 (09) : 70 - 74
  • [7] Toward public-key infrastructure interoperability
    Backhouse, J
    Hsu, C
    McDonnell, A
    COMMUNICATIONS OF THE ACM, 2003, 46 (06) : 98 - 100
  • [8] Profiles and protocols for the Internet Public-Key Infrastructure
    Adams, C
    Lloyd, S
    PROCEEDINGS OF THE SIXTH IEEE COMPUTER SOCIETY WORKSHOP ON FUTURE TRENDS OF DISTRIBUTED COMPUTING SYSTEMS, 1997, : 220 - 224
  • [9] Implementing public-key infrastructure for sensor networks
    Malan, David J.
    Welsh, Matt
    Smith, Michael D.
    ACM TRANSACTIONS ON SENSOR NETWORKS, 2008, 4 (04)
  • [10] ARPKI: Attack Resilient Public-Key Infrastructure
    Basin, David
    Cremers, Cas
    Kim, Tiffany Hyun-Jin
    Perrig, Adrian
    Sasse, Ralf
    Szalachowski, Pawel
    CCS'14: PROCEEDINGS OF THE 21ST ACM CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2014, : 382 - 393