DTKI: A New Formalized PKI with Verifiable Trusted Parties - INRIA - Institut National de Recherche en Informatique et en Automatique Accéder directement au contenu
Article Dans Une Revue The Computer Journal Année : 2016

DTKI: A New Formalized PKI with Verifiable Trusted Parties

Résumé

The security of public key validation protocols for web-based applications has recently attracted attention because of weaknesses in the certificate authority model, and consequent attacks. Recent proposals using public logs have succeeded in making certificate management more transparent and verifiable. However, those proposals involve a fixed set of authorities. This means an oligopoly is created. Another problem with current log-based system is their heavy reliance on trusted parties that monitor the logs. We propose a distributed transparent key infrastructure (DTKI), which greatly reduces the oligopoly of service providers and allows verification of the behaviour of trusted parties. In addition, this paper formalises the public log data structure and provides a formal analysis of the security that DTKI guarantees.
Fichier principal
Vignette du fichier
YCR-tcj16.pdf (951.54 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-01403899 , version 1 (28-11-2016)

Licence

Paternité

Identifiants

Citer

Jiangshan Yu, Vincent Cheval, Mark Ryan. DTKI: A New Formalized PKI with Verifiable Trusted Parties. The Computer Journal, 2016, 59, pp.1695-1713. ⟨10.1093/comjnl/bxw039⟩. ⟨hal-01403899⟩
289 Consultations
130 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More