跳到主要导航 跳到搜索 跳到主要内容

X-FTPC: A Fine-Grained Trust Propagation Control Scheme for Cross-Certification Utilizing Certificate Transparency

  • University of Science and Technology of China
  • Ningxia University

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

Cross-certification plays a fundamental role in facilitating the interconnection between different root stores in public key infrastructure (PKI). However, the existing trust management schemes (e.g., certificate extension) cannot implement fine-grained control over the trust propagation caused by cross-signing. This leads to the fact that although cross-certification expands the trust scope of certificate authorities (CAs), it also brings new security risks to the existing PKI system: (a) makes the certification path in PKI more complicated and lacks effective control, resulting in the arbitrary propagation of trust, and (b) more seriously, may even cause a revoked Cross-signed CA to continue to issue certificates that still have valid trust paths, due to the presence of cross-certificates that have not been fully revoked. Certificate Transparency (CT) is proposed to detect maliciously or mistakenly issued certificates and improve the accountability of CAs, by recording all certificates in publicly-visible logs. In this paper, we propose X-FTPC, a fine-grained trust propagation control enhancement scheme for cross-certification based on the idea of transparency, combined with the publicly-accessible, auditable, and append-only features of the CT log. X-FTPC introduces a new certificate extension to force the cross-signed CA to submit an end-entity certificate to the specified log for pre-verification before it can be finally accepted. Fine-grained control of cross-certificate trust propagation is achieved through real-time monitoring of the certificate issuing behavior of cross-signed CAs. Moreover, it is fully compatible with CT frameworks that are widely deployed on the Internet.

源语言英语
主期刊名Applied Cryptography in Computer and Communications - 2nd EAI International Conference, AC3 2022, Proceedings
编辑Jingqiang Lin, Qiang Tang
出版商Springer Science and Business Media Deutschland GmbH
123-138
页数16
ISBN(印刷版)9783031170805
DOI
出版状态已出版 - 2022
活动2nd EAI International Conference on Applied Cryptography in Computer and Communications, AC3 2022 - Virtual, Online
期限: 14 5月 202215 5月 2022

出版系列

姓名Lecture Notes of the Institute for Computer Sciences, Social-Informatics and Telecommunications Engineering, LNICST
448 LNICST
ISSN(印刷版)1867-8211
ISSN(电子版)1867-822X

会议

会议2nd EAI International Conference on Applied Cryptography in Computer and Communications, AC3 2022
Virtual, Online
时期14/05/2215/05/22

指纹

探究 'X-FTPC: A Fine-Grained Trust Propagation Control Scheme for Cross-Certification Utilizing Certificate Transparency' 的科研主题。它们共同构成独一无二的指纹。

引用此