SOSP2024

NOPE: Strengthening domain authentication with succinct proofs

Zachary DeStefano, Jeff J. Ma, Joseph Bonneau, Michael Walfish

2 citations

Abstract

Server authentication assures users that they are communicating with a server that genuinely represents a claimed domain. Today, server authentication relies on certification authorities (CAs), third parties who sign statements binding public keys to domains. CAs remain a weak spot in Internet security, as any faulty CA can issue a certificate for any domain.