F-PKI: Enabling Innovation and Trust Flexibility in the HTTPS Public-Key Infrastructure

08/19/2021
by   Laurent Chuat, et al.
0

We present F-PKI, an enhancement to the HTTPS public-key infrastructure that gives trust flexibility to both clients and domain owners while giving certification authorities (CAs) means to enforce stronger security measures. In today's web PKI, all CAs are equally trusted, and security is defined by the weakest link. We address this problem by introducing trust flexibility in two dimensions: with F-PKI, each domain owner can define a domain policy (specifying, for example, which CAs are authorized to issue certificates for their domain name) and each client can set or choose a validation policy based on trust levels. F-PKI thus supports a property that is sorely needed in today's Internet: trust heterogeneity. Different parties can express different trust preferences while still being able to verify all certificates. In contrast, today's web PKI only allows clients to fully distrust suspicious/misbehaving CAs, which is likely to cause collateral damage in the form of legitimate certificates being rejected. Our contribution is to present a system that is backward compatible, provides sensible security properties to both clients and domain owners, ensures the verifiability of all certificates, and prevents downgrade attacks. Furthermore, F-PKI provides a ground for innovation, as it gives CAs an incentive to deploy new security measures to attract more customers, without having these measures undercut by vulnerable CAs.

READ FULL TEXT
research
05/02/2020

Who Needs Trust for 5G?

There has been much recent discussion of the criticality of the 5G infra...
research
01/25/2023

The Synchronic Web

The Synchronic Web is a distributed network for securing data provenance...
research
09/02/2021

TLS Beyond the Broker: Enforcing Fine-grained Security and Trust in Publish/Subscribe Environments for IoT

Message queuing brokers are a fundamental building block of the Internet...
research
04/12/2018

A Metapolicy Framework for Enhancing Domain Expressiveness on the Internet

Domain Name System (DNS) domains became Internet-level identifiers for e...
research
09/25/2019

PDoT: Private DNS-over-TLS with TEE Support

Security and privacy of the Internet Domain Name System (DNS) have been ...
research
09/18/2020

The Boon and Bane of Cross-Signing: Shedding Light on a Common Practice in Public Key Infrastructures

Public Key Infrastructures (PKIs) with their trusted Certificate Authori...
research
01/31/2021

A Trust-Based Approach for Volunteer-Based Distributed Computing in the Context of Biological Simulation

As simulating complex biological processes become more important for mod...

Please sign up or login with your details

Forgot password? Click here to reset