CertLedger: A New PKI Model with Certificate Transparency Based on Blockchain

06/11/2018
by   Murat Yasin Kubilay, et al.
0

In conventional PKI, CAs are assumed to be fully trusted. However, in practice, CAs' absolute responsibility for providing trustworthiness caused major security and privacy issues. To prevent such issues, Google introduced the concept of Certificate Transparency (CT) in 2013. Later, several new PKI models (e.g., AKI, ARPKI, and DTKI) are proposed to reduce the level of trust to the CAs. However, all of these proposals are still vulnerable to split-world attacks if the adversary is capable of showing different views of the log to the targeted victims. In this paper, we propose a new PKI architecture with certificate transparency based on blockchain, what we called CertLedger, to eliminate the split-world attacks and to provide an ideal certificate/revocation transparency. All TLS certificates, their revocation status, entire revocation process, and trusted CA management are conducted in the CertLedger. CertLedger provides a unique, efficient, and trustworthy certificate validation process eliminating the conventional inadequate and incompatible certificate validation processes implemented by different software vendors. TLS clients in the CertLedger also do not require to make certificate validation and store the trusted CA certificates anymore. We analyze the security and performance of the CertLedger and provide a comparison with the previous proposals.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
01/13/2020

Characterizing the Root Landscape of Certificate Transparency Logs

Internet security and privacy stand on the trustworthiness of public cer...
research
04/03/2018

Blockchain-based TLS Notary Service

The Transport Layer Security (TLS) protocol is a de facto standard of se...
research
07/17/2018

BARS: a Blockchain-based Anonymous Reputation System for Trust Management in VANETs

The public key infrastructure (PKI) based authentication protocol provid...
research
04/21/2023

Decentralized Inverse Transparency With Blockchain

Employee data can be used to facilitate work, but their misusage may pos...
research
06/30/2021

Extending On-chain Trust to Off-chain - A Trustworthy Vaccine Shipping Example

Blockchain creates a secure environment on top of strict cryptographic a...
research
11/20/2017

Software Distribution Transparency and Auditability

A large user base relies on software updates provided through package ma...
research
02/08/2021

Revocation Statuses on the Internet

The modern Internet is highly dependent on the trust communicated via X....

Please sign up or login with your details

Forgot password? Click here to reset