Server Location Verification (SLV) and Server Location Pinning: Augmenting TLS Authentication

被引:11
作者
Abdou, Abdelrahman [1 ]
Van Oorschot, P. C. [1 ]
机构
[1] Carleton Univ, Sch Comp Sci, 1125 Colonel Dr, Ottawa, ON K1S 5B6, Canada
关键词
Server authentication; SSL/TLS; location-based authentication; internet measurements; INTERNET; GEOLOCATION;
D O I
10.1145/3139294
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
We introduce the first known mechanism providing realtime server location verification. Its uses include enhancing server authentication by enabling browsers to automatically interpret server location information. We describe the design of this new measurement-based technique, Server Location Verification (SLV), and evaluate it using PlanetLab. We explain how SLV is compatible with the increasing trends of geographically distributed content dissemination over the Internet, without causing any new interoperability conflicts. Additionally, we introduce the notion of (verifiable) server location pinning (conceptually similar to certificate pinning) to support SLV, and evaluate their combined impact using a server-authentication evaluation framework. The results affirm the addition of new security benefits to the existing TLS-based authentication mechanisms. We implement SLV through a location verification service, the simplest version of which requires no server-side changes. We also implement a simple browser extension that interacts seamlessly with the verification infrastructure to obtain realtime server location-verification results.
引用
收藏
页数:26
相关论文
共 55 条
[1]  
3GPP, 2015, 23271 3GPP TS
[2]   Accurate Manipulation of Delay-based Internet Geolocation [J].
Abdou, AbdelRahman ;
Matrawy, Ashraf ;
van Oorschot, Paul C. .
PROCEEDINGS OF THE 2017 ACM ASIA CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (ASIA CCS'17), 2017, :887-898
[3]   CPV: Delay-Based Location Verification for the Internet [J].
Abdou, AbdelRahman ;
Matrawy, Ashraf ;
van Oorschot, P. C. .
IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2017, 14 (02) :130-144
[4]  
Adelsbach A, 2005, LECT NOTES COMPUT SC, V3439, P204
[5]  
Agricola Ilka, 2008, ELEMENTARY GEOMETRY, V43
[6]  
Akamai, 2015, FACTS FIG
[7]  
[Anonymous], 2003, BLACKH C EUR 14 15 M
[8]  
[Anonymous], 2012, P 2012 ACM C COMP CO
[9]  
[Anonymous], 2011, TECHNICAL REPORT, DOI null
[10]  
[Anonymous], 2006, P SIGCHI C HUM FACT, DOI 10.1145/1124772.1124861