IKP: Turning a PKI Around with Decentralized Automated Incentives

2017 IEEE Symposium on Security and Privacy (SP)(2017)

引用 251|浏览100
暂无评分
摘要
Despite a great deal of work to improve the TLS PKI, CA misbehavior continues to occur, resulting in unauthorized certificates that can be used to mount man-in-the-middle attacks against HTTPS sites. CAs lack the incentives to invest in higher security, and the manual effort required to report a rogue certificate deters many from contributing to the security of the TLS PKI. In this paper, we present IKP, a platform that automates responses to unauthorized certificates and provides incentives for CAs to behave correctly and for others to report potentially unauthorized certificates. Domains in IKP specify criteria for their certificates, and CAs specify reactions such as financial penalties that execute in case of unauthorized certificate issuance. By leveraging smart contracts and blockchain-based consensus, we can decentralize IKP while still providing automated incentives. We describe a theoretical model for payment flows and implement IKP in Ethereum to show that decentralizing and automating PKIs with financial incentives is both economically sound and technically viable.
更多
查看译文
关键词
Instant Karma PKI,public key infrastructure,IKP,decentralized automated incentives,unauthorized certificates,man-in-the-middle attacks,HTTPS sites,certificate authorities,CA,smart contracts,blockchain-based consensus,Ethereum,transport layer security,TLS,World Wide Web
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要