arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

证书透明度及其变体中的问责性

Accountability in Certificate Transparency and Variants

Timo Treitz, Robert Künnemann

arXiv 2609.11552首次发表:更新:

发表机构

Saarland University; CISPA Helmholtz Center for Information Security(萨尔兰州立大学; CISPA赫尔霍兹信息安全中心)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本文在Dolev-Yao模型下分析证书透明度及其扩展的问责性,证明普通CT依赖诚实日志,SCT审计可消除该假设,而八卦传播不能。

AI 中文摘要

证书透明度(CT)旨在减少TLS证书生态系统中对证书颁发机构(CA)的信任需求。所有主流浏览器均支持该协议。该协议要求所有CA将其签发的证书记录在公共日志中,而该日志本身由第三方监控其合规性和一致性。鉴于CA、日志服务器、监控方以及最终用户客户端这四个角色之间复杂的检查机制,很难精确说明CT如何以复杂基础设施为代价消除信任假设。Dolev-Yao范式和计算范式中的分析仅涉及非常简化的模型,且其特性定义专门针对CA,本质上捕捉的是设计特征而非目标属性。本文提出将问责性作为CT的主要目标,并在Dolev-Yao模型中进行了深入分析。我们从原始PKI开始,逐步过渡到CT,最终分析了SCT审计和八卦传播的拟议扩展。我们证明,普通CT依赖于诚实的日志服务器,但在此假设下提供了问责性。此外,我们表明SCT审计扩展可以消除这一假设,而八卦传播扩展则不能。

英文摘要

Certificate Transparency (CT) aims to reduce the trust required in Certificate Authorities (CAs) within the TLS certificate ecosystem. It is supported by all major browsers. The protocol obliges all CAs to record the certificates they issue in a public log, which itself is monitored for compliance and consistency by third parties. Given this complex set of checks between the four roles-CA, loggers, monitor but also the end user's client-it is very hard to provide a precise account of how CT eliminates trust assumptions in exchange for complex infrastructure. Analyses both in the Dolev-Yao paradigm and the computational paradigm only regard a very simplified model and feature definitions adapted specifically to CAs, essentially capturing design features rather than the target property. The present paper posits accountability as the main goal of CT and presents a thorough analysis in the Dolev-Yao model. We start with the vanilla PKI and, step by step, move to CT, finally analyzing proposed extensions for SCT Auditing and Gossiping. We show that plain CT relies on an honest log, but provides accountability under this assumption. Furthermore, we show that the SCT Auditing extension can eliminate this assumption, while the Gossiping extension cannot.

Commentsfull version of CCS'2026 paper

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑