IKP: Turning a PKI Around with Decentralized Automated Incentives
Stephanos Matsumoto, Raphael M. Reischuk
Abstract
Despite a great deal of work to improve the TLS PKI, CA misbehavior continues to occur, resulting in unauthorized certificates that can be used to mount man-in-themiddle attacks against HTTPS sites. CAs lack the incentives to invest in higher security, and the manual effort required to report a rogue certificate deters many from contributing to the security of the TLS PKI. In this paper, we present IKP, a platform that automates responses to unauthorized certificates and provides incentives for CAs to behave correctly and for others to report potentially unauthorized certificates. Domains in IKP specify criteria for their certificates, and CAs specify reactions such as financial penalties that execute in case of unauthorized certificate issuance. By leveraging smart contracts and blockchain-based consensus, we can decentralize IKP while still providing automated incentives. We describe a theoretical model for payment flows and implement IKP in Ethereum to show that decentralizing and automating PKIs with financial incentives is both economically sound and technically viable. Domain Certificate Policy (DCP)
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a622678f-3c5c-4e4a-93b1-f02206d625e1Cited by top-tier papers5
- Merkle2: A Low-Latency Transparency Log SystemYuncong Hu, Kian Hooshmand, Harika Kalidhindi, Seung Jin Yang et al.S&P 2021 · 51 citations
- iBatch: saving Ethereum fees via secure and cost-effective batching of smart-contract invocationsYibo Wang, Qi Zhang, Kai Li, Yuzhe Tang et al.FSE 2021 · 15 citations
- Decentralized Crowdsourcing for Human Intelligence Tasks with Efficient On-Chain CostYihuai Liang, Yan Li, Byeong-Seok ShinVLDB 2022 · 9 citations
- CTng: Secure Certificate and Revocation TransparencyJie Kong, James Damon, Hemi Leibowitz, Ewa Syta et al.NDSS 2026 · 5 citations
- Droplet: Decentralized Authorization and Access Control for Encrypted Data StreamsHossein Shafagh, Lukas Burkhalter, Sylvia Ratnasamy, Anwar HithnawiUSENIX Security 2020
Builds on3
- Hawk: The Blockchain Model of Cryptography and Privacy-Preserving Smart ContractsAhmed E. Kosba, Andrew Miller, Elaine Shi, Zikai Wen et al.S&P 2016 · 2,201 citations
- Town Crier: An Authenticated Data Feed for Smart ContractsFan Zhang, Ethan Cecchetti, Kyle Croman, Ari Juels et al.CCS 2016 · 668 citations
- Keeping Authorities "Honest or Bust" with Decentralized Witness CosigningEwa Syta, Iulia Tamas, Dylan Visher, David Isaac Wolinsky et al.S&P 2016 · 285 citations
Related papers
- Bamboozling Certificate Authorities with BGPHenry Birge-Lee, Yixin Sun, Anne Edmundson, Jennifer Rexford et al.USENIX Security 2018 · 83 citations
- F-PKI: Enabling Innovation and Trust Flexibility in the HTTPS Public-Key InfrastructureLaurent Chuat, Cyrill Krähenbühl, Prateek Mittal, Adrian PerrigNDSS 2022
- Tracking Certificate Misissuance in the WildDeepak Kumar, Zhengping Wang, Matthew Hyder, Joseph Dickinson et al.S&P 2018 · 86 citations
- TLS-N: Non-repudiation over TLS Enablign Ubiquitous Content SigningHubert Ritzdorf, Karl Wüst, Arthur Gervais, Guillaume Felley et al.NDSS 2018 · 32 citations
- What's in a Name? Exploring CA Certificate ControlZane Ma, Joshua Mason, Manos Antonakakis, Zakir Durumeric et al.USENIX Security 2021 · 16 citations
