SmartCert: Redesigning Digital Certificates with Smart Contracts

03/30/2020
by   Pawel Szalachowski, et al.
0

The Transport Layer Security (TLS) protocol and its public-key infrastructure (PKI) are widely used in the Internet to achieve secure communication. Validating domain ownership by trusted certification authorities (CAs) is a critical step in issuing digital certificates, but unfortunately, this process provides a poor security level. In this work, we present SmartCert, a novel approach based on smart contracts to improve digital certificates. A certificate in SmartCert conveys detailed information about its validation state which is constantly changing but only with respect to the specified smart contract code and individual domain policies. CAs issuing and updating certificates are kept accountable and their actions are transparent and monitored by the code. We present the implementation and evaluation of SmartCert, and discuss its deployability.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
06/04/2018

Securify: Practical Security Analysis of Smart Contracts

Permissionless blockchains allow the execution of arbitrary programs (ca...
research
01/04/2019

VeriSolid: Correct-by-Design Smart Contracts for Ethereum

The adoption of blockchain based distributed ledgers is growing fast due...
research
09/25/2018

BlockPKI: An Automated, Resilient, and Transparent Public-Key Infrastructure

This paper describes BlockPKI, a blockchain-based public-key infrastruct...
research
04/29/2020

AuthSC: Mind the Gap between Web and Smart Contracts

Although almost all information about Smart Contract addresses is shared...
research
01/13/2020

Formal specification of a security framework for smart contracts

As smart contracts are growing in size and complexity, it becomes harder...
research
06/02/2023

Proxy Re-encryption based Fair Trade Protocol for Digital Goods Transactions via Smart Contracts

With the massive amount of digital data generated everyday, transactions...
research
03/15/2021

Compositional Security for Reentrant Applications

The disastrous vulnerabilities in smart contracts sharply remind us of o...

Please sign up or login with your details

Forgot password? Click here to reset