中文
相关论文

相关论文: Reducing Trust in Automated Certificate Authoritie…

200 篇论文

Certification Authority Authentication (CAA) is a safeguard against illegitimate certificate issuance. We show how shortcomings in CAA concepts and operational aspects undermine its effectiveness in preventing certificate misissuance. Our…

密码学与安全 · 计算机科学 2026-02-06 Pouyan Fotouhi Tehrani , Raphael Hiesgen , Thomas C. Schmidt , Matthias Wählisch

The security of TLS depends on trust in certificate authorities, and that trust stems from their ability to protect and control the use of a private signing key. The signing key is the key asset of a certificate authority (CA), and its…

密码学与安全 · 计算机科学 2017-10-11 Bargav Jayaraman , Hannah Li , David Evans

Many of the benefits we derive from the Internet require trust in the authenticity of HTTPS connections. Unfortunately, the public key certification ecosystem that underwrites this trust has failed us on numerous occasions. Towards an…

密码学与安全 · 计算机科学 2018-01-04 Jan-Ole Malchow , Benjamin Güldenring , Volker Roth

Public Key Infrastructures (PKIs) with their trusted Certificate Authorities (CAs) provide the trust backbone for the Internet: CAs sign certificates which prove the identity of servers, applications, or users. To be trusted by operating…

密码学与安全 · 计算机科学 2020-09-21 Jens Hiller , Johanna Amann , Oliver Hohlfeld

AI-enabled tools have become sophisticated enough to allow a small number of individuals to run disinformation campaigns of an unprecedented scale. Privacy-preserving identity attestations can drastically reduce instances of impersonation…

密码学与安全 · 计算机科学 2023-11-29 Shrey Jain , Connor Spelliscy , Samuel Vance-Law , Scott Moore

Certificate transparency (CT) is an elegant mechanism designed to detect when a certificate authority (CA) has issued a certificate incorrectly. Many CAs now support CT and it is being actively deployed in browsers. However, a number of…

密码学与安全 · 计算机科学 2017-08-08 Saba Eskandarian , Eran Messeri , Joseph Bonneau , Dan Boneh

Continuous Authentication (CA) has been proposed as a potential solution to counter complex cybersecurity attacks that exploit conventional static authentication mechanisms that authenticate users only at an ingress point. However, widely…

密码学与安全 · 计算机科学 2020-10-13 Syed W. Shah , Naeem F. Syed , Arash Shaghaghi , Adnan Anwar , Zubair Baig , Robin Doss

The signing key protection of Certificate Authorities (CAs) remains a critical challenge in PKI. Traditional approaches struggle to eliminate the risk of key exposure due to those (un)intentional human errors. This long-standing dilemma…

密码学与安全 · 计算机科学 2025-01-14 Xiaolin Zhang , Chenghao Chen , Kailun Qin , Yuxuan Wang , Shipei Qu , Tengfei Wang , Chi Zhang , Dawu Gu

A Certificate Authority (CA) provides the critical authentication and security services for Public Key Infrastructure (PKI) which are used for the Internet and wired networks. In MANETs (wireless and ad hoc) there is an inability to offer a…

网络与互联网体系结构 · 计算机科学 2018-12-14 Junaid Chaudhry , Kashif Saleem , Paul Haskell-Dowland , Mahdi H. Miraz

The Transport Layer Security (TLS) protocol and its public-key infrastructure (PKI) are widely used in the Internet to achieve secure communication. Validating domain ownership by trusted certification authorities (CAs) is a critical step…

密码学与安全 · 计算机科学 2020-03-31 Pawel Szalachowski

The Web public key infrastructure is essential to providing secure communication on the Internet today, and certificate authorities play a crucial role in this ecosystem by issuing certificates. These authorities may misissue certificates…

密码学与安全 · 计算机科学 2022-03-04 Sarah Meiklejohn , Joe DeBlasio , Devon O'Brien , Chris Thompson , Kevin Yeo , Emily Stark

The advance of web services technologies promises to have far-reaching effects on the Internet and enterprise networks allowing for greater accessibility of data. The security challenges presented by the web services approach are…

计算机科学中的逻辑 · 计算机科学 2012-06-15 Michele Barletta , Silvio Ranise , Luca Viganò

This paper introduces Generalized Quantum-assisted Digital Signature (GQaDS), an improved version of a recently proposed scheme whose information theoretic security is inherited by adopting QKD keys for digital signature purposes. Its…

密码学与安全 · 计算机科学 2024-07-01 Alberto Tarable , Rudi Paolo Paganelli , Elisabetta Storelli , Alberto Gatto , Marco Ferrari

Browsers can detect malicious websites that are provisioned with forged or fake TLS/SSL certificates. However, they are not so good at detecting malicious websites if they are provisioned with mistakenly issued certificates or certificates…

密码学与安全 · 计算机科学 2017-07-21 Abhishek Singh , Binanda Sengupta , Sushmita Ruj

Certificates ensure the authenticity of users' public keys, however their overhead (e.g., certificate chains) might be too costly for some IoT systems like aerial drones. Certificate-free cryptosystems, like identity-based and…

密码学与安全 · 计算机科学 2021-03-18 Rouzbeh Behnia , Attila A. Yavuz , Muslum Ozgur Ozmen , Tsz Hon Yuen

Authentication with username and password is becoming an inconvenient process for the user. End users typically have little control over their personal privacy, and data breaches effecting millions of users have already happened several…

分布式、并行与集群计算 · 计算机科学 2020-06-09 Zoltán András Lux , Dirk Thatmann , Sebastian Zickau , Felix Beierle

We describe TrustBase, an architecture that provides certificate-based authentication as an operating system service. TrustBase enforces best practices for certificate validation for all applications and transparently enables existing…

密码学与安全 · 计算机科学 2016-10-28 Mark O'Neill , Scott Heidbrink , Jordan Whitehead , Scott Ruoti , Dan Bunker , Kent Seamons , Daniel Zappala

Cloud-based services have become part of our day-to-day software solutions. The identity authentication process is considered to be the main gateway to these services. As such, these gates have become increasingly susceptible to aggressive…

密码学与安全 · 计算机科学 2017-11-27 Marwan Darwish , Abdelkader Ouda , Luiz Fernando Capretz

We propose a capability-based access control technique for sharing Web resources, based on Verifiable Credentials (VCs) and OAuth 2.0. VCs are a secure means for expressing claims about a subject. Although VCs are ideal for encoding…

密码学与安全 · 计算机科学 2021-04-30 Nikos Fotiou , Vasilios A. Siris , George C. Polyzos

Passwords are a fragile, inadequate, and insecure tool for authenticating users, and are especially fraught with problems when used to secure access to network resources and services. In many cases, passwords provide a false sense of…

密码学与安全 · 计算机科学 2012-09-06 Travis Z. Suel
‹ 上一页 1 2 3 10 下一页 ›