Blockchain-Based Certificate Transparency and Revocation Transparency

被引:49
|
作者
Wang, Ze [1 ,2 ]
Lin, Jingqiang [1 ,2 ,3 ]
Cai, Quanwei [1 ,2 ]
Wang, Qiongxiao [1 ,2 ,3 ]
Zha, Daren [1 ,2 ]
Jing, Jiwu [4 ]
机构
[1] Chinese Acad Sci, Inst Informat Engn, State Key Lab Informat Secur LOIS, Beijing 100864, Peoples R China
[2] Chinese Acad Sci, Data Assurance & Commun Secur Res Ctr DCS Ctr, Beijing 100864, Peoples R China
[3] Univ Chinese Acad Sci, Sch Cyber Secur, Beijing 100049, Peoples R China
[4] Univ Chinese Acad Sci, Sch Comp Sci & Technol, Beijing 100049, Peoples R China
基金
中国国家自然科学基金;
关键词
Web servers; Blockchain; Browsers; Publishing; Public key; certificate transparency; certificate revocation; public key infrastructure; trust management;
D O I
10.1109/TDSC.2020.2983022
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Traditional X.509 public key infrastructures (PKIs) depend on trusted certification authorities (CAs) to sign certificates, used in SSL/TLS to authenticate web servers and establish secure channels. However, recent security incidents indicate that CAs may (be compromised to) sign fraudulent certificates. In this article, we propose blockchain-based certificate transparency (CT) and revocation transparency (RT) to balance the absolute authority of CAs. Our scheme is compatible with X.509 PKIs but significantly reinforces the security guarantees of a certificate. The CA-signed certificates and their revocation status information of an SSL/TLS web server are published by the subject (i.e., the web server) as a transaction in the global certificate blockchain. The certificate blockchain acts as append-only public logs to monitor CAs' certificate signing and revocation operations, and an SSL/TLS web server is granted with the cooperative control on its certificates. A browser compares the certificate received in SSL/TLS negotiations with the ones in the public certificate blockchain, and accepts it only if it is published and not revoked. We implement the prototype system with Firefox and Nginx, and the experimental results show that it introduces reasonable overheads.
引用
下载
收藏
页码:681 / 697
页数:17
相关论文
共 50 条
  • [1] Enhancing Security of Certificate Authorities by Blockchain-based Domain Transparency
    Xiong, Qin
    Zhang, Yujian
    Li, Junhao
    Tong, Fei
    2022 IEEE 28TH INTERNATIONAL CONFERENCE ON PARALLEL AND DISTRIBUTED SYSTEMS, ICPADS, 2022, : 304 - 311
  • [2] BRT: An Efficient and Scalable Blockchain-Based Revocation Transparency System for TLS Connections
    Xing, Qianqian
    Wang, Xiaofeng
    Xu, Xinyue
    Lin, Jiaqi
    Wang, Fei
    Li, Cui
    Wang, Baosheng
    SENSORS, 2023, 23 (21)
  • [3] Certificate Transparency Using Blockchain
    Madala, D. S. V.
    Jhanwar, Mahabir Prasad
    Chattopadhyay, Anupam
    2018 18TH IEEE INTERNATIONAL CONFERENCE ON DATA MINING WORKSHOPS (ICDMW), 2018, : 71 - 80
  • [4] Private Status Retrieval for Blockchain-based Certificate Revocation System
    Ruan, Zhichao
    Ye, Wei
    Xie, Yankai
    Li, Haixing
    Zhang, Chi
    Wei, Lingbo
    ICC 2023-IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, 2023, : 6565 - 6570
  • [5] A blockchain-based certificate revocation management and status verification system
    Adja, Yves Christian Elloh
    Hammi, Badis
    Serhrouchni, Ahmed
    Zeadally, Sherali
    COMPUTERS & SECURITY, 2021, 104
  • [6] Blockchain-Based Collaborative Certificate Revocation Systems Using Clustering
    Didouh, Ahmed
    Labiod, Houda
    El Hillali, Yassin
    Rivenq, Atika
    IEEE ACCESS, 2022, 10 : 51487 - 51500
  • [7] MSChain: Blockchain based Decentralized Certificate Transparency for Microservices
    Dilshan, Dulaj
    Piumika, Supimi
    Rupasinghe, Chameera
    Perera, Indika
    Siriwardena, Prabath
    MERCON 2020: 6TH INTERNATIONAL MULTIDISCIPLINARY MORATUWA ENGINEERING RESEARCH CONFERENCE (MERCON), 2020, : 638 - 643
  • [8] Blockchain-Based Data Transparency: Issues and Challenges
    Meng X.
    Liu L.
    Liu, Lixin (99liulixin@163.com), 1600, Science Press (58): : 237 - 252
  • [9] Blockchain-based Automated Certificate Revocation for 5G IoT
    Hewa, Tharaka
    Braeken, An
    Ylianttila, Mika
    Liyana, Madhusanka
    ICC 2020 - 2020 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2020,
  • [10] CertLedger: A new PKI model with Certificate Transparency based on blockchain
    Kubilay, Murat Yasin
    Kiraz, Mehmet Sabir
    Mantar, Hact Ali
    COMPUTERS & SECURITY, 2019, 85 : 333 - 352