New Directions for Trust in the Certificate Authority Ecosystem

01/03/2018
by   Jan-Ole Malchow, et al.
0

Many of the benefits we derive from the Internet require trust in the authenticity of HTTPS connections. Unfortunately, the public key certification ecosystem that underwrites this trust has failed us on numerous occasions. Towards an exploration of the root causes we present an update to the common knowledge about the Certificate Authority (CA) ecosystem. Based on our findings the certificate ecosystem currently undergoes a drastic transformation. Big steps towards ubiquitous encryption were made, however, on the expense of trust for authentication of communication partners. Furthermore we describe systemic problems rooted in misaligned incentives between players in the ecosystem. We depict that proposed security extensions do not correctly realign these incentives. As such we argue that it is worth considering alternative methods of authentication. As a first step in this direction we propose an insurance-based mechanism and we demonstrate that it is technically feasible.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
02/14/2022

A Systematic Literature Review on Trust in the Software Ecosystem

We conduct a systematic literature review on the concept of trust in the...
research
04/17/2021

Towards Fortifying the Multi-Factor-Based Online Account Ecosystem

With the rapid growth of online services, the number of online accounts ...
research
01/15/2021

TrustSECO: An Interview Survey into Software Trust

The software ecosystem is a trust-rich part of the world. Collaborativel...
research
08/29/2020

A Formal Security Analysis of the pEp Authentication Protocol for Decentralized Key Distribution and End-to-End Encrypted Email

To send encrypted emails, users typically need to create and exchange ke...
research
02/17/2023

Towards Zero-trust Security for the Metaverse

By focusing on immersive interaction among users, the burgeoning Metaver...
research
10/26/2020

On the Root of Trust Identification Problem

Root of Trust Identification (RTI) refers to determining whether a given...
research
02/12/2019

Achieving Trust-Based and Privacy-Preserving Customer Selection in Ubiquitous Computing

The recent proliferation of smart devices has given rise to ubiquitous c...

Please sign up or login with your details

Forgot password? Click here to reset