中文
相关论文

相关论文: Do CAA, CT, and DANE Interlink in Certificate Depl…

200 篇论文

During disasters, crisis, and emergencies the public relies on online services provided by official authorities to receive timely alerts, trustworthy information, and access to relief programs. It is therefore crucial for the authorities to…

密码学与安全 · 计算机科学 2021-04-15 Pouyan Fotouhi Tehrani , Eric Osterweil , Jochen H. Schiller , Thomas C. Schmidt , Matthias Wählisch

A new certification authority authorization (CAA) resource record for the domain name system (DNS) was standardized in 2013. Motivated by the later 2017 decision to enforce mandatory CAA checking for most certificate authorities, this paper…

密码学与安全 · 计算机科学 2019-09-06 Jukka Ruohonen

In this paper, we analyze the evolution of Certificate Transparency (CT) over time and explore the implications of exposing certificate DNS names from the perspective of security and privacy. We find that certificates in CT logs have seen…

网络与互联网体系结构 · 计算机科学 2018-11-12 Quirin Scheitle , Oliver Gasser , Theodor Nolte , Johanna Amann , Lexi Brent , Georg Carle , Ralph Holz , Thomas C. Schmidt , Matthias Wählisch

Certification Authority Authentication (CAA) is a safeguard against illegitimate certificate issuance. We show how shortcomings in CAA concepts and operational aspects undermine its effectiveness in preventing certificate misissuance. Our…

密码学与安全 · 计算机科学 2026-02-06 Pouyan Fotouhi Tehrani , Raphael Hiesgen , Thomas C. Schmidt , Matthias Wählisch

Public Key Infrastructures (PKIs) with their trusted Certificate Authorities (CAs) provide the trust backbone for the Internet: CAs sign certificates which prove the identity of servers, applications, or users. To be trusted by operating…

密码学与安全 · 计算机科学 2020-09-21 Jens Hiller , Johanna Amann , Oliver Hohlfeld

The Domain Name System (DNS) serves as the backbone of the Internet, primarily translating domain names to IP addresses. Over time, various enhancements have been introduced to strengthen the integrity of DNS. Among these, DNSSEC stands out…

密码学与安全 · 计算机科学 2025-12-09 Aduma Rishith , Aditya Kulkarni , Tamal Das , Vivek Balachandran

Phishing attacks remain a persistent cybersecurity threat, and the widespread adoption of TLS certificates has unintentionally enabled malicious websites to appear trustworthy to users. This study examines whether certificate metadata and…

Transport Layer Security (TLS) is the base for many Internet applications and services to achieve end-to-end security. In this paper, we provide guidance on how to measure TLS deployments, including X.509 certificates and Web PKI. We…

网络与互联网体系结构 · 计算机科学 2024-02-01 Pouyan Fotouhi Tehrani , Eric Osterweil , Thomas C. Schmidt , Matthias Wählisch

The security of TLS depends on trust in certificate authorities, and that trust stems from their ability to protect and control the use of a private signing key. The signing key is the key asset of a certificate authority (CA), and its…

密码学与安全 · 计算机科学 2017-10-11 Bargav Jayaraman , Hannah Li , David Evans

Using a total of 4,774 hospitals categorized as government, non-profit, and proprietary hospitals, this study provides the first measurement-based analysis of hospitals' websites and connects the findings with data breaches through a…

密码学与安全 · 计算机科学 2023-04-27 Mohammed Alkinoon , Abdulrahman Alabduljabbar , Hattan Althebeiti , Rhongho Jang , DaeHun Nyang , David Mohaisen

The Transport Layer Security (TLS) protocol and its public-key infrastructure (PKI) are widely used in the Internet to achieve secure communication. Validating domain ownership by trusted certification authorities (CAs) is a critical step…

密码学与安全 · 计算机科学 2020-03-31 Pawel Szalachowski

Internet security and privacy stand on the trustworthiness of public certificates signed by Certificate Authorities (CAs). However, software products do not trust the same CAs and therefore maintain different root stores, each typically…

网络与互联网体系结构 · 计算机科学 2021-02-01 Nikita Korzhitskii , Niklas Carlsson

The 2013 National Security Agency revelations of pervasive monitoring have lead to an "encryption rush" across the computer and Internet industry. To push back against massive surveillance and protect users privacy, vendors, hosting and…

密码学与安全 · 计算机科学 2017-06-20 Maarten Aertsen , Maciej Korczyński , Giovane C. M. Moura , Samaneh Tajalizadehkhoob , Jan van den Berg

Today, Internet offers many critical applications. So, it becomes very crucial for Internet service providers to ensure traceability of operations and to secure data exchange. Since all these communications are based on the use of the…

密码学与安全 · 计算机科学 2012-08-01 Kaouthar Chetioui , Ghizlane Orhanou , Said El Hajji , Abdelmajid Lakbabi

A Certificate Authority (CA) provides the critical authentication and security services for Public Key Infrastructure (PKI) which are used for the Internet and wired networks. In MANETs (wireless and ad hoc) there is an inability to offer a…

网络与互联网体系结构 · 计算机科学 2018-12-14 Junaid Chaudhry , Kashif Saleem , Paul Haskell-Dowland , Mahdi H. Miraz

Experience shows that most researchers and developers tend to treat plain-domains (those that are not prefixed with "www" sub-domains, e.g. "example.com") as synonyms for their equivalent www-domains (those that are prefixed with "www"…

密码学与安全 · 计算机科学 2019-06-19 Eman Salem Alashwali , Pawel Szalachowski , Andrew Martin

Content Delivery Networks (CDNs) offer a protection layer for enhancing the security of websites. However, a significant security flaw named Absence of Domain Verification (DVA) has become emerging recently. Although this threat is…

密码学与安全 · 计算机科学 2024-09-04 Ziyu Lin , Zhiwei Lin , Run Guo , Jianjun Chen , Mingming Zhang , Ximeng Liu , Tianhao Yang , Zhuoran Cao , Robert H. Deng

The domain name system translates human friendly web addresses to a computer readable internet protocol address. This basic infrastructure is insecure and can be manipulated. Deployment of technology to secure the DNS system has been slow,…

计算机与社会 · 计算机科学 2017-12-15 Robert Robinson

The threats of caching poisoning attacks largely stimulate the deployment of DNSSEC. Being a strong but demanding cryptographical defense, DNSSEC has its universal adoption predicted to go through a lengthy transition. Thus the DNSSEC…

密码学与安全 · 计算机科学 2016-02-29 Zheng Wang

The emergence of quantum computers poses a significant threat to current secure service, application and/or protocol implementations that rely on RSA and ECDSA algorithms, for instance DNSSEC, because public-key cryptography based on number…

密码学与安全 · 计算机科学 2025-07-15 Julio Gento Suela , Javier Blanco-Romero , Florina Almenares Mendoza , Daniel Díaz-Sánchez
‹ 上一页 1 2 3 10 下一页 ›