• DocumentCode
    2858565
  • Title

    PorKI: making user PKI safe on machines of heterogeneous trustworthiness

  • Author

    Sinclair, Sara ; Smith, Sean W.

  • Author_Institution
    Dept. of Comput. Sci., Dartmouth Coll., Hanover, NH
  • fYear
    2005
  • fDate
    5-9 Dec. 2005
  • Lastpage
    430
  • Abstract
    As evidenced by the proliferation of phishing attacks and keystroke loggers, we know that human beings are not well-equipped to make trust decisions about when to use their passwords or other personal credentials. Public key cryptography can reduce this risk of attack, because authentication using PKI is designed to not give away sensitive data. However, using private keys on standard platforms exposes the user to "keyjacking"; mobile users wishing to use keypairs on an unfamiliar and potentially untrusted workstation face even more obstacles. In this paper we present the design and prototype of PorKI, a software application for mobile devices that offers an alternative solution to the portable key problem. Through the use of temporary keypairs, proxy certificates, and wireless protocols, PorKI enables a user to employ her PKI credentials on any Bluetooth-enabled workstation, including those not part of her organization\´s network, and even those that might be malicious. Moreover, by crafting XACML policy statements that limit the key usage to the workstation\´s trustworthiness level, and inserting these statements into extensions of the proxy certificates, PorKI provides the user or the relying party with the ability to limit the amount of trust that can be put in the temporary keypair used on that workstation, and thus the scope of a potential compromise
  • Keywords
    Bluetooth; mobile computing; public key cryptography; PorKI; XACML policy statements; authentication; heterogeneous trustworthiness; mobile software; portable key problem; private keys; public key cryptography; Application software; Authentication; Computer science; Educational institutions; Humans; Public key; Public key cryptography; Software prototyping; Wireless application protocol; Workstations;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Security Applications Conference, 21st Annual
  • Conference_Location
    Tucson, AZ
  • ISSN
    1063-9527
  • Print_ISBN
    0-7695-2461-3
  • Type

    conf

  • DOI
    10.1109/CSAC.2005.43
  • Filename
    1565269