liu.seSearch for publications in DiVA
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • oxford
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Trust Issue(r)s: Certificate Revocation and Replacement Practices in the Wild
Linköping University.
Linköping University.
Linköping University, Department of Computer and Information Science, Database and information techniques. Linköping University, Faculty of Science & Engineering.ORCID iD: 0009-0005-9031-6600
University of Calgary, Canada.
Show others and affiliations
2024 (English)In: Passive and Active Measurement: 25th International Conference, PAM 2024. Virtual Event, March 11–13, 2024. Proceedings, Part II. / [ed] Philipp Richter, Vaibhav Bajpai, Esteban Carisimo, Cham, Switzerland: Springer Nature, 2024, Vol. 14538, p. 293-321Conference paper, Published paper (Refereed)
Abstract [en]

Every time we use the web, we place our trust in X.509 certificates binding public keys to domain identities. However, for these certificates to be trustworthy, proper issuance, management, and timely revocations (in cases of compromise or misuse) are required. While great efforts have been placed on ensuring trustworthiness in the issuance of new certificates, there has been a scarcity of empirical studies on revocation management. This study offers the first comprehensive analysis of certificate replacements (CRs) of revoked certificates. It provides a head-to-head comparison of the CRs where the replaced certificate was revoked versus not revoked. Leveraging two existing datasets with overlapping timelines, we create a combined dataset containing 1.5 million CRs that we use to unveil valuable insights into the effect of revocations on certificate management. Two key questions guide our research: (1) the influence of revocations on certificate replacement behavior and (2) the effectiveness of revocations in fulfilling their intended purpose. Our statistical analysis reveals significant variations in revocation rates, retention rates, and post-revocation usage, shedding light on differences in Certificate Authorities' (CAs) practices and subscribers' decisions. Notably, a substantial percentage of revoked certificates were either observed or estimated to be used after revocation, raising concerns about key-compromise instances. Finally, our findings highlight shortcomings in existing revocation protocols and practices, emphasizing the need for improvements. We discuss ongoing efforts and potential solutions to address these issues, offering valuable guidance for enhancing the security and integrity of web communications.

Place, publisher, year, edition, pages
Cham, Switzerland: Springer Nature, 2024. Vol. 14538, p. 293-321
Series
Lecture Notes in Computer Science, ISSN 0302-9743, E-ISSN 1611-3349 ; 14538
National Category
Computer Sciences
Identifiers
URN: urn:nbn:se:liu:diva-201892DOI: 10.1007/978-3-031-56252-5_14ISI: 001209301100014ISBN: 9783031562518 (print)ISBN: 9783031562525 (electronic)OAI: oai:DiVA.org:liu-201892DiVA, id: diva2:1846836
Conference
25th International Conference on Passive and Active Network Measurement (PAM), Virtual Event, March 11–13, 2024
Funder
Wallenberg AI, Autonomous Systems and Software Program (WASP)
Note

This work was partially supported by the Wallenberg AI, Autonomous Systems and Software Program (WASP) funded by the Knut and Alice Wallenberg Foundation.

Available from: 2024-03-25 Created: 2024-03-25 Last updated: 2024-05-31

Open Access in DiVA

fulltext(915 kB)42 downloads
File information
File name FULLTEXT01.pdfFile size 915 kBChecksum SHA-512
e3cb9e5cc2c62294e0db654efb2d84125f4e465a0860f1432f002e7c4020bceb6572c2f6387c1faa7c227380a2fa2d3b68975191aba64087e554dfa94e71c950
Type fulltextMimetype application/pdf

Other links

Publisher's full text

Authority records

Bruhner, Carl MagnusCarlsson, Niklas

Search in DiVA

By author/editor
Cerenius, DavidKaller, MartinBruhner, Carl MagnusCarlsson, Niklas
By organisation
Linköping UniversityDatabase and information techniquesFaculty of Science & Engineering
Computer Sciences

Search outside of DiVA

GoogleGoogle Scholar
Total: 42 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

doi
isbn
urn-nbn

Altmetric score

doi
isbn
urn-nbn
Total: 193 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • oxford
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf