Overview on Security Issues of Certificate Transparency
CSTR:
Author:
Affiliation:

Clc Number:

Fund Project:

  • Article
  • |
  • Figures
  • |
  • Metrics
  • |
  • Reference
  • |
  • Related
  • |
  • Cited by
  • |
  • Materials
  • |
  • Comments
    Abstract:

    Public Key Infrastructure (PKI) and SSL/TLS encryption are key elements of today's Internet for secure communications, but a major security risk is caused by an compromised or malicious CA. In 2013, Google proposed Certificate Transparency (CT) which aimed to safeguard the certificate issuance process by providing an open framework for monitoring and auditing HTTPS certificates. At present, in Google ecology, CT is being actively supported by most of CA, and developed in browsers. Meanwhile, a number of secure-related challenges remain. This article reviews the CT technology from the perspectives of trust mechanism and security threats, summarizes the CT-based Web-PKI trust model and security threat model, and puts forward the security assurance mechanism and application deployment recommendations. Finally, the development of CT technology is summarized and prospected.

    Reference
    Related
    Cited by
Get Citation

张婕,王伟,马迪,毛伟.数字证书透明性CT机制安全威胁研究.计算机系统应用,2018,27(10):232-239

Copy
Share
Article Metrics
  • Abstract:
  • PDF:
  • HTML:
  • Cited by:
History
  • Received:January 31,2018
  • Revised:February 27,2018
  • Adopted:
  • Online: September 29,2018
  • Published:
Article QR Code
You are the firstVisitors
Copyright: Institute of Software, Chinese Academy of Sciences Beijing ICP No. 05046678-3
Address:4# South Fourth Street, Zhongguancun,Haidian, Beijing,Postal Code:100190
Phone:010-62661041 Fax: Email:csa (a) iscas.ac.cn
Technical Support:Beijing Qinyun Technology Development Co., Ltd.

Beijing Public Network Security No. 11040202500063