Proceedings 2015 Workshop on Security of Emerging Networking Technologies 2015
DOI: 10.14722/sent.2015.23009
|View full text |Cite
|
Sign up to set email alerts
|

Certificates-as-an-Insurance: Incentivizing Accountability in SSL/TLS

Abstract: We propose to leverage accountability mechanisms to deal with trust-related security incidents of certification authorities (CAs) in the SSL/TLS public-key infrastructure (PKI). We argue that, despite recent advances in securing certificate issuance and verification, the TLS PKI does not sufficiently incentivize careful identity verification by CAs during certificate issuance or provide CA accountability in the event of a certificate compromise. We propose a new paradigm, Certificates-as-an-Insurance, to hold … Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
5
0
1

Year Published

2015
2015
2023
2023

Publication Types

Select...
7
1

Relationship

1
7

Authors

Journals

citations
Cited by 12 publications
(6 citation statements)
references
References 14 publications
0
5
0
1
Order By: Relevance
“…Matsumoto and Reischuk [33] suggested to incentivize CAs for careful identity validation by making them financially accountable. In case of a security incident, an insurance payout should be triggered automatically to the domain owner.…”
Section: Related Workmentioning
confidence: 99%
“…Matsumoto and Reischuk [33] suggested to incentivize CAs for careful identity validation by making them financially accountable. In case of a security incident, an insurance payout should be triggered automatically to the domain owner.…”
Section: Related Workmentioning
confidence: 99%
“…Entretanto, pesquisas demonstram que muitas vezes o ecossistema do HTTPŚ e, diferentemente do imaginado (ou do senso comum), inseguro [Bokslag 2016, Frost et al 2019, Samarasinghe and Mannan 2019. Os desafios e problemas de segurança são muitos e podem ocorrer em diferentes partes do ecossistema, incluindo falhas na especificação ou implementação dos protocolos, falhas na configuração dos certificados digitais nos servidores Web, falhas na geração dos certificados digitais, vulnerabilidades na Infraestrutura de Chaves Públicas (ICP), entre outras vulnerabilidades [Bokslag 2016, Frost et al 2019, Samarasinghe and Mannan 2019, Matsumoto and Reischuk 2015, Merzdovnik et al 2016.…”
Section: Navegação Segura (?) Na Internet Com Httpsunclassified
“…More recently, Matsumoto and Reischuk [19] made a case for tying certificates with insurances as a means to improve the accountability of CAs. The model they propose differs from ours in crucial aspects.…”
Section: Related Modelsmentioning
confidence: 99%