About | Contact Us | Register | Login
ProceedingsSeriesJournalsSearchEAI
Applied Cryptography in Computer and Communications. Second EAI International Conference, AC3 2022, Virtual Event, May 14-15, 2022, Proceedings

Research Article

X-FTPC: A Fine-Grained Trust Propagation Control Scheme for Cross-Certification Utilizing Certificate Transparency

Cite
BibTeX Plain Text
  • @INPROCEEDINGS{10.1007/978-3-031-17081-2_8,
        author={Shushang Wen and Bingyu Li and Ziqiang Ma and Qianhong Wu and Nenghai Yu},
        title={X-FTPC: A Fine-Grained Trust Propagation Control Scheme for Cross-Certification Utilizing Certificate Transparency},
        proceedings={Applied Cryptography in Computer and Communications. Second EAI International Conference, AC3 2022, Virtual Event, May 14-15, 2022, Proceedings},
        proceedings_a={AC3},
        year={2022},
        month={10},
        keywords={Public key infrastructure Certificate transparency Cross certification Cross-signing Trust management},
        doi={10.1007/978-3-031-17081-2_8}
    }
    
  • Shushang Wen
    Bingyu Li
    Ziqiang Ma
    Qianhong Wu
    Nenghai Yu
    Year: 2022
    X-FTPC: A Fine-Grained Trust Propagation Control Scheme for Cross-Certification Utilizing Certificate Transparency
    AC3
    Springer
    DOI: 10.1007/978-3-031-17081-2_8
Shushang Wen1, Bingyu Li2,*, Ziqiang Ma3, Qianhong Wu2, Nenghai Yu1
  • 1: School of Cyber Science and Technology, University of Science and Technology of China
  • 2: School of Cyber Science and Technology, Beihang University
  • 3: School of Information Engineering, Ningxia University
*Contact email: libingyu@buaa.edu.cn

Abstract

Cross-certification plays a fundamental role in facilitating the interconnection between different root stores in public key infrastructure (PKI). However, the existing trust management schemes (e.g.,certificate extension) cannot implement fine-grained control over the trust propagation caused by cross-signing. This leads to the fact that although cross-certification expands the trust scope of certificate authorities (CAs), it also brings new security risks to the existing PKI system: (a) makes the certification path in PKI more complicated and lacks effective control, resulting in the arbitrary propagation of trust, and (b) more seriously, may even cause a revoked Cross-signed CA to continue to issue certificates that still have valid trust paths, due to the presence of cross-certificates that have not been fully revoked. Certificate Transparency (CT) is proposed to detect maliciously or mistakenly issued certificates and improve the accountability of CAs, by recording all certificates in publicly-visible logs. In this paper, we proposeX-FTPC, a fine-grained trust propagation control enhancement scheme for cross-certification based on the idea of transparency, combined with the publicly-accessible, auditable, and append-only features of the CT log.X-FTPCintroduces a new certificate extension to force the cross-signed CA to submit an end-entity certificate to the specified log for pre-verification before it can be finally accepted. Fine-grained control of cross-certificate trust propagation is achieved through real-time monitoring of the certificate issuing behavior of cross-signed CAs. Moreover, it is fully compatible with CT frameworks that are widely deployed on the Internet.

Keywords
Public key infrastructure Certificate transparency Cross certification Cross-signing Trust management
Published
2022-10-06
Appears in
SpringerLink
http://dx.doi.org/10.1007/978-3-031-17081-2_8
Copyright © 2022–2025 ICST
EBSCOProQuestDBLPDOAJPortico
EAI Logo

About EAI

  • Who We Are
  • Leadership
  • Research Areas
  • Partners
  • Media Center

Community

  • Membership
  • Conference
  • Recognition
  • Sponsor Us

Publish with EAI

  • Publishing
  • Journals
  • Proceedings
  • Books
  • EUDL