Private Queries on Public Certificate Transparency Data

05/13/2019
by   Vy-An Phan, et al.
0

Despite increasing advancements in today's information exchange infrastructure, the preservation of user data and privacy still remains a problem. Both insecure baselines and secure solutions leak user data. For example, Certificate Transparency (CT) promises significant security improvements to existing Public Key Infrastructure solutions that up-to-now have solely relied on the Certificate Authority hierarchy. CT provides a robust auditing layer and transparency solution to quickly detect such compromises, but introduces the requirement that client browsers interact with third-party servers when validating a site certificate. In the existing CT system, these requests leak information about each user's browsing habits to the hosting server. It is not a stretch to think that this valuable data could be collected and exploited, as corporations and governments have plenty of financial and political incentive to do so. In this project, we seek to address this problem by using an oblivious file sharing system with strong anonymity properties, to provide a more scalable, performant solution to privacy-preserving queries.

READ FULL TEXT
research
03/03/2022

SoK: SCT Auditing in Certificate Transparency

The Web public key infrastructure is essential to providing secure commu...
research
07/29/2019

Secure Exchange of Digital Goods in a Decentralized Data Marketplace

We are tackling the problem of trading real-world private information us...
research
06/01/2018

Oblivious DNS: Practical Privacy for DNS Queries

Every Internet communication typically involves a Domain Name System (DN...
research
12/22/2017

Contour: A Practical System for Binary Transparency

Transparency is crucial in security-critical applications that rely on a...
research
10/13/2021

3LSAA: A Secure And Privacy-preserving Zero-knowledge-based Data-sharing Approach Under An Untrusted Environment

As data collection and analysis become critical functions for many cloud...
research
09/21/2018

The Rise of Certificate Transparency and Its Implications on the Internet Ecosystem

In this paper, we analyze the evolution of Certificate Transparency (CT)...
research
10/28/2022

Ethereum, IPFS and neural compression to decentralize and protect patient data in computational pathology

The field of digital pathology produces a large number of images associa...

Please sign up or login with your details

Forgot password? Click here to reset