The Experts below are selected from a list of 27 Experts worldwide ranked by ideXlab platform

Marriages - One of the best experts on this subject based on the ideXlab platform.

Thaier Hayajneh - One of the best experts on this subject based on the ideXlab platform.

  • UEMCON - Security issues with Certificate authorities
    2017 IEEE 8th Annual Ubiquitous Computing Electronics and Mobile Communication Conference (UEMCON), 2017
    Co-Authors: Jake A. Berkowsky, Thaier Hayajneh
    Abstract:

    The current state of the internet relies heavily on SSL/TLS and the Certificate authority model. This model has systematic problems, both in its design as well as its implementation. There are problems with Certificate Revocation, Certificate authority governance, breaches, poor security practices, single points of failure and with root stores. This paper begins with a general introduction to SSL/TLS and a description of the role of Certificates, Certificate authorities and root stores in the current model. This paper will then explore problems with the current model and describe work being done to help mitigate these problems.

  • Security issues with Certificate authorities
    2017 IEEE 8th Annual Ubiquitous Computing Electronics and Mobile Communication Conference (UEMCON), 2017
    Co-Authors: Jake A. Berkowsky, Thaier Hayajneh
    Abstract:

    The current state of the internet relies heavily on SSL/TLS and the Certificate authority model. This model has systematic problems, both in its design as well as its implementation. There are problems with Certificate Revocation, Certificate authority governance, breaches, poor security practices, single points of failure and with root stores. This paper begins with a general introduction to SSL/TLS and a description of the role of Certificates, Certificate authorities and root stores in the current model. This paper will then explore problems with the current model and describe work being done to help mitigate these problems.

Jake A. Berkowsky - One of the best experts on this subject based on the ideXlab platform.

  • UEMCON - Security issues with Certificate authorities
    2017 IEEE 8th Annual Ubiquitous Computing Electronics and Mobile Communication Conference (UEMCON), 2017
    Co-Authors: Jake A. Berkowsky, Thaier Hayajneh
    Abstract:

    The current state of the internet relies heavily on SSL/TLS and the Certificate authority model. This model has systematic problems, both in its design as well as its implementation. There are problems with Certificate Revocation, Certificate authority governance, breaches, poor security practices, single points of failure and with root stores. This paper begins with a general introduction to SSL/TLS and a description of the role of Certificates, Certificate authorities and root stores in the current model. This paper will then explore problems with the current model and describe work being done to help mitigate these problems.

  • Security issues with Certificate authorities
    2017 IEEE 8th Annual Ubiquitous Computing Electronics and Mobile Communication Conference (UEMCON), 2017
    Co-Authors: Jake A. Berkowsky, Thaier Hayajneh
    Abstract:

    The current state of the internet relies heavily on SSL/TLS and the Certificate authority model. This model has systematic problems, both in its design as well as its implementation. There are problems with Certificate Revocation, Certificate authority governance, breaches, poor security practices, single points of failure and with root stores. This paper begins with a general introduction to SSL/TLS and a description of the role of Certificates, Certificate authorities and root stores in the current model. This paper will then explore problems with the current model and describe work being done to help mitigate these problems.

Peter Loshin - One of the best experts on this subject based on the ideXlab platform.

Sugih Jamin - One of the best experts on this subject based on the ideXlab platform.

  • Windowed Key Revocation in Public Key Infrastructures
    2020
    Co-Authors: Patrick Mcdaniel, Sugih Jamin
    Abstract:

    A fundamental problem inhibiting the wide acceptance of a Public Key Infrastructure (PKI) in the Internet is the lack of a mechanism that provides scalable Certificate Revocation. In this paper, we propose a novel mechanism called Windowed Revocation. In windowed Revocation, Certificate Revocation is announced for short periods in periodic Certificate Revocation Lists (CRLs). Due to the assurances provided by the protocol over which Certificates are retrieved, we bound the amount of time that any Certificate is cached by users. Thus, we can limit the announcement of Revocation only to the time in which the Certificate may be cached; not until its expiration. Because the time in which Certificate are announced is short, CRLs are similarly small. By limiting the size of CRLs, we are able to integrate other mechanisms that increase the scalability of the PKI. One such mechanism is the use of “pushed” CRLs using multicast. We include a proof of the correctness of our approach.