Blockchain-Based Certificate Transparency and Revocation Transparency

被引:49
|
作者
Wang, Ze [1 ,2 ]
Lin, Jingqiang [1 ,2 ,3 ]
Cai, Quanwei [1 ,2 ]
Wang, Qiongxiao [1 ,2 ,3 ]
Zha, Daren [1 ,2 ]
Jing, Jiwu [4 ]
机构
[1] Chinese Acad Sci, Inst Informat Engn, State Key Lab Informat Secur LOIS, Beijing 100864, Peoples R China
[2] Chinese Acad Sci, Data Assurance & Commun Secur Res Ctr DCS Ctr, Beijing 100864, Peoples R China
[3] Univ Chinese Acad Sci, Sch Cyber Secur, Beijing 100049, Peoples R China
[4] Univ Chinese Acad Sci, Sch Comp Sci & Technol, Beijing 100049, Peoples R China
基金
中国国家自然科学基金;
关键词
Web servers; Blockchain; Browsers; Publishing; Public key; certificate transparency; certificate revocation; public key infrastructure; trust management;
D O I
10.1109/TDSC.2020.2983022
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Traditional X.509 public key infrastructures (PKIs) depend on trusted certification authorities (CAs) to sign certificates, used in SSL/TLS to authenticate web servers and establish secure channels. However, recent security incidents indicate that CAs may (be compromised to) sign fraudulent certificates. In this article, we propose blockchain-based certificate transparency (CT) and revocation transparency (RT) to balance the absolute authority of CAs. Our scheme is compatible with X.509 PKIs but significantly reinforces the security guarantees of a certificate. The CA-signed certificates and their revocation status information of an SSL/TLS web server are published by the subject (i.e., the web server) as a transaction in the global certificate blockchain. The certificate blockchain acts as append-only public logs to monitor CAs' certificate signing and revocation operations, and an SSL/TLS web server is granted with the cooperative control on its certificates. A browser compares the certificate received in SSL/TLS negotiations with the ones in the public certificate blockchain, and accepts it only if it is published and not revoked. We implement the prototype system with Firefox and Nginx, and the experimental results show that it introduces reasonable overheads.
引用
收藏
页码:681 / 697
页数:17
相关论文
共 50 条
  • [31] Enhancing Transparency and Trust in Agrifood Supply Chains through Novel Blockchain-based Architecture
    Sakthivel, V
    Prakash, P.
    Lee, Jae-Woo
    Prabu, P.
    KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2024, 18 (07): : 1968 - 1985
  • [32] Blockchain-based governance models supporting corruption-transparency: A systematic literature review
    Ibrahimy, Mohammad Mustafa
    Norta, Alex
    Normak, Peeter
    BLOCKCHAIN-RESEARCH AND APPLICATIONS, 2024, 5 (02):
  • [33] A blockchain based certificate revocation scheme for vehicular communication systems
    Lei, Ao
    Cao, Yue
    Bao, Shihan
    Li, Dasen
    Asuquo, Philip
    Cruickshank, Haitham
    Sun, Zhili
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2020, 110 (110): : 892 - 903
  • [34] Certificate Transparency With Enhanced Privacy
    Kwon, Hyunsoo
    Lee, Sangtae
    Kim, Minjae
    Hahn, Changhee
    Hur, Junbeom
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2023, 20 (05) : 3860 - 3872
  • [35] Implementing multisignature on a blockchain-based land administration system: Securing land rights and enhancing transparency
    Tahar, Attoumane
    Mendy, Gervais
    Ouya, Samuel
    PROCEEDINGS OF 2023 5TH BLOCKCHAIN AND INTERNET OF THINGS CONFERENCE, BIOTC 2023, 2023, : 8 - 14
  • [36] Blockchain-Based Implementation of National Census as a Supplementary Instrument for Enhanced Transparency, Accountability, Privacy, and Security
    Rasheed, Sana
    Louca, Soulla
    FUTURE INTERNET, 2024, 16 (01)
  • [38] Towards a blockchain-based certificate authentication system in Vietnam
    Binh Minh Nguyen
    Thanh-Chung Dao
    Ba-Lam Do
    PEERJ COMPUTER SCIENCE, 2020, 2020 (03)
  • [39] Software Architecture for Blockchain-based Trade Certificate Systems
    Lu, Qinghua
    Staples, Mark
    OConnor, Hugo
    Chen, Shiping
    Guabtni, Adnene
    2020 IEEE INTERNATIONAL CONFERENCE ON BLOCKCHAIN AND CRYPTOCURRENCY (IEEE ICBC), 2020,
  • [40] A survey on blockchain-based student certificate management system
    Sarala, M.
    Muralidhara, B. L.
    14TH INTERNATIONAL CONFERENCE ON THEORY AND PRACTICE OF ELECTRONIC GOVERNANCE (ICEGOV 2021), 2021, : 44 - 50