CTng: Secure Certificate and Revocation Transparency
Jie Kong, James Damon, Hemi Leibowitz, Ewa Syta, Amir Herzberg
Abstract
We present CTng, an evolutionary and practical PKI design that efficiently addresses multiple key challenges faced by deployed PKI systems. CTng ensures strong security properties, including guaranteed transparency of certificates and guaranteed, unequivocal revocation, achieved under NTTP-security, i.e., without requiring trust in any single CA, logger, or relying party. These guarantees hold even in the presence of arbitrary corruptions of these entities, assuming only a known bound (f ) of corrupt monitors (e.g., f = 8), with minimal performance impact. CTng also enables efficient certificate validation and preserves relying-party privacy, while providing scalable and efficient distribution of revocation updates. These properties significantly improve upon current PKI designs. In particular, while Certificate Transparency (CT) [35] , [36], [37] aims to eliminate single points of trust, the existing specification [36] still assumes benign loggers. Addressing this through log redundancy is possible, but rather inefficient, limiting deployed configurations to f ≤ 2. We present a security analysis and an evaluation of our opensource CTng prototype, showing that it is efficient and scalable under realistic deployment conditions. I. INTRODUCTION The Public Key Infrastructure (PKI) facilitates the secure use of public keys. PKI is critical for the security of open, distributed systems such as the Internet. Typically, a relying party obtains a public key and validates it using a certificate signed by a trusted Certificate Authority (CA). The PKI defines how certificates are issued and revoked (by the CAs) and validated (by relying parties). Most deployed PKIs follow the X.509 standard [8], [24]. X.509 certificates are used in protocols such as TLS, SSH, S/MIME, IPsec, and others. The most common application of PKI is to secure web and other forms of communication § The work was partially completed during the author's PhD studies at the
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 6ca644a9-5fa1-47a6-becb-cba94b71bef3Cited by top-tier papers4
- RHINE: Robust and High-performance Internet Naming with E2E AuthenticityHuayi Duan, Rubén Fischer, Jie Lou, Si Liu et al.NSDI 2023 · 12 citations
- SoK: Cryptographic Authenticated DictionariesHarjasleen Malvai, Francesca Falzon, Andrew Zitek-Estrada, Sarah Meiklejohn et al.NDSS 2026 · 2 citations
- Transparent Dictionaries from Polynomial CommitmentsHossein Hafezi, Alireza Shirzad, Benedikt Bünz, Joseph BonneauUSENIX Security 2026 · 1 citation
- Accountability in Certificate Transparency and VariantsTimo Treitz, Robert KünnemannCCS 2026
Builds on8
- Keeping Authorities "Honest or Bust" with Decentralized Witness CosigningEwa Syta, Iulia Tamas, Dylan Visher, David Isaac Wolinsky et al.S&P 2016 · 285 citations
- Narwhal and Tusk: a DAG-based mempool and efficient BFT consensusGeorge Danezis, Lefteris Kokoris-Kogias, Alberto Sonnino, Alexander SpiegelmanEuroSys 2022 · 259 citations
- IKP: Turning a PKI Around with Decentralized Automated IncentivesStephanos Matsumoto, Raphael M. ReischukS&P 2017 · 168 citations
- Catena: Efficient Non-equivocation via BitcoinAlin Tomescu, Srinivas DevadasS&P 2017 · 144 citations
- DispersedLedger: High-Throughput Byzantine Consensus on Variable Bandwidth NetworksLei Yang, Seo Jin Park, Mohammad Alizadeh, Sreeram Kannan et al.NSDI 2022 · 120 citations
Related papers
- Does Certificate Transparency Break the Web? Measuring Adoption and Error RateEmily Stark, Ryan Sleevi, Rijad Muminovic, Devon O'Brien et al.S&P 2019 · 44 citations
- Pruning the Tree: Rethinking RPKI Architecture from the Ground upHaya Schulmann, Niklas VogelNDSS 2026 · 1 citation
- On Re-engineering the X.509 PKI with Executable Specification for Better Implementation GuaranteesJoyanta Debnath, Sze Yiu Chau, Omar ChowdhuryCCS 2021 · 8 citations
- On the Unnecessary Complexity of Names in X.509 and Their Impact on ImplementationsYuteng Sun, Joyanta Debnath, Wenzheng Hong, Omar Chowdhury et al.FSE 2025
- CRLite: A Scalable System for Pushing All TLS Revocations to All BrowsersJames Larisch, David R. Choffnes, Dave Levin, Bruce M. Maggs et al.S&P 2017 · 105 citations
