DocumentCode :
612053
Title :
SoK: SSL and HTTPS: Revisiting Past Challenges and Evaluating Certificate Trust Model Enhancements
Author :
Clark, J. ; van Oorschot, Paul C.
Author_Institution :
Sch. of Comput. Sci., Carleton Univ., Ottawa, ON, Canada
fYear :
2013
fDate :
19-22 May 2013
Firstpage :
511
Lastpage :
525
Abstract :
Internet users today depend daily on HTTPS for secure communication with sites they intend to visit. Over the years, many attacks on HTTPS and the certificate trust model it uses have been hypothesized, executed, and/or evolved. Meanwhile the number of browser-trusted (and thus, de facto, user-trusted) certificate authorities has proliferated, while the due diligence in baseline certificate issuance has declined. We survey and categorize prominent security issues with HTTPS and provide a systematic treatment of the history and on-going challenges, intending to provide context for future directions. We also provide a comparative evaluation of current proposals for enhancing the certificate infrastructure used in practice.
Keywords :
Internet; online front-ends; security of data; transport protocols; HTTPS; Internet users; SSL; SoK; baseline certificate issuance; browser-trusted certificate authority; certificate trust model enhancements; Browsers; Cryptography; Organizations; Protocols; Servers; Software; SSL; browser trust model; certificates; usability;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Security and Privacy (SP), 2013 IEEE Symposium on
Conference_Location :
Berkeley, CA
ISSN :
1081-6011
Print_ISBN :
978-1-4673-6166-8
Electronic_ISBN :
1081-6011
Type :
conf
DOI :
10.1109/SP.2013.41
Filename :
6547130
Link To Document :
بازگشت