中文
相关论文

相关论文: Misbinding Raw Public Keys to Identities in TLS

200 篇论文

Security and Privacy are crucial in modern Internet services. Transport Layer Security (TLS) has largely addressed the issue of security. However, information about the type of service being accessed goes in plain-text in the initial…

密码学与安全 · 计算机科学 2022-07-06 Vinod S. Khandkar , Manjesh K. Hanawal , Sameer G Kulkarni

As 5G networks expand into critical infrastructure, secure and efficient user authentication is more important than ever. The 5G-AKA protocol, standardized by 3GPP in TS 33.501, is central to authentication in current 5G deployments. It…

密码学与安全 · 计算机科学 2025-07-29 Nazatul H. Sultan , Xinlong Guan , Josef Pieprzyk , Wei Ni , Sharif Abuadbba , Hajime Suzuki

The Resource Public Key Infrastructure (RPKI) is the main mechanism to protect inter-domain routing with BGP from prefix hijacks. It has already been widely deployed by large providers and the adoption rate is getting to a critical point.…

密码学与安全 · 计算机科学 2024-08-23 Donika Mirdita , Haya Schulmann , Michael Waidner

Quantum computing represents an emerging threat to the public key infrastructure underlying transport layer security (TLS) widely used in the Internet. This paper describes how QKD symmetric keys can be used with TLS to provide quantum…

密码学与安全 · 计算机科学 2020-07-13 Bernardo Huberman , Bob Lund , Jing Wang

This document presents TLS and how to make it secure enough as of 2014 Spring. Of course all the information given here will rot with time. Protocols known as secure will be cracked and will be replaced with better versions. Fortunately we…

密码学与安全 · 计算机科学 2014-07-09 Emmanuel Dreyfus

Network fingerprinting is used to identify applications, provide insight into network traffic, and detect malicious activity. With the broad adoption of TLS, traditional fingerprinting techniques that rely on clear-text data are no longer…

密码学与安全 · 计算机科学 2020-09-07 Blake Anderson , David McGrew

In this paper, we consider the problem of verifying anonymity and unlinkability in the symbolic model, where protocols are represented as processes in a variant of the applied pi calculus, notably used in the ProVerif tool. Existing tools…

密码学与安全 · 计算机科学 2019-04-09 Lucca Hirschi , David Baelde , Stéphanie Delaune

Secure Shell (SSH) protocol requires all implementations to support public key authentication method ("publickey") for authentication purposes, so web applications which provide a SSH client over the web browser need to support "publickey".…

密码学与安全 · 计算机科学 2015-06-17 Dorai Ashok Shanmugavel Anbalagan

The Resource Public Key Infrastructure (RPKI) protocol was standardized to add cryptographic security to Internet routing. With over 50% of Internet resources protected with RPKI today, the protocol already impacts significant parts of…

密码学与安全 · 计算机科学 2024-09-24 Haya Schulmann , Niklas Vogel , Michael Waidner

As the quantum computing era approaches, securing classical cryptographic protocols becomes imperative. Public key cryptography is widely used for signature and key exchange but it is the type of cryptography more threatened by quantum…

密码学与安全 · 计算机科学 2026-01-19 Grazia D'Onghia , Diana Gratiela Berbecaru , Antonio Lioy

Vehicular networks are used to coordinate actions among vehicles in traffic by the use of wireless transceivers (pairs of transmitters and receivers). Unfortunately, the wireless communication among vehicles is vulnerable to security…

密码学与安全 · 计算机科学 2015-07-17 Shlomi Dolev , Łukasz Krzywiecki , Nisha Panwar , Michael Segal

Though not yet widely deployed, password-authenticated key exchange (PAKE) protocols have been the subject of several recent standardization efforts, partly because of their resistance against various guessing attacks, but also because they…

密码学与安全 · 计算机科学 2026-02-10 Eloise Christian , Tejas Gadwalkar , Arthur Azevedo de Amorim , Edward V. Zieglar

Network traffic inspection, including TLS traffic, in enterprise environments is widely practiced. Reasons for doing so are primarily related to improving enterprise security (e.g., malware detection) and meeting legal requirements. To…

密码学与安全 · 计算机科学 2018-09-25 Louis Waked , Mohammad Mannan , Amr Youssef

The centralized PKI is not a suitable solution to provide identities in large-scale IoT systems. The main problem is the high cost of managing X.509 certificates throughout their lifecycle, from installation to regular updates and…

密码学与安全 · 计算机科学 2024-02-14 Leonardo Perugini , Andrea Vesco

As of today, TLS is the most commonly used protocol to protect communication content. To provide good security, it is of central importance, that administrators know how to configure their services correctly. For this purpose, services…

人机交互 · 计算机科学 2018-09-25 Christian Tiefenau , Emanuel von Zezschwitz

Transport Layer Security (TLS) protocol is a cryptographic protocol designed to secure communication over the internet. The TLS protocol has become a fundamental in secure communication, most commonly used for securing web browsing…

密码学与安全 · 计算机科学 2024-09-30 Maciej Kalka , Marek Kirejczyk

Identity verification is the process of confirming an individual's claimed identity, which is essential in sectors like finance, healthcare, and online services to ensure security and prevent fraud. However, current password/PIN-based…

密码学与安全 · 计算机科学 2025-07-22 Yao Ma , Wen Yu Kon , Jefferson Chu , Kevin Han Yong Loh , Kaushik Chakraborty , Charles Lim

Remote Keyless Entry (RKE) systems have become a standard feature in modern vehicles, yet their unidirectional fixed-frequency radio communication renders them vulnerable to replay attacks, impersonation attacks, cryptanalysis, and…

密码学与安全 · 计算机科学 2025-04-15 Jingjing Guo , Bo Tang , Jiayuan Xu , Qingyi Li , Yuyuan Qin , Xinghua Li

This paper describes a new protocol for authentication in ad-hoc networks. The protocol has been designed to meet specialized requirements of ad-hoc networks, such as lack of direct communication between nodes or requirements for revocable…

密码学与安全 · 计算机科学 2007-05-23 Adam Wierzbicki , Aneta Zwierko , Zbigniew Kotulski

Since Remote Keyless Entry (RKE) systems started to be widely used, several vulnerabilities in their protocols have been found. Attacks such as jamming-and-replay attacks and relay attacks are still effective against most recent RKE…

密码学与安全 · 计算机科学 2019-05-16 Vanesa Daza , Xavier Salleras