CTng: Secure Certificate and Revocation Transparency
Jie Kong, James Damon, Hemi Leibowitz, Ewa Syta, Amir Herzberg
摘要
We present CTng, an evolutionary and practical PKI design that efficiently addresses multiple key challenges faced by deployed PKI systems. CTng ensures strong security properties, including guaranteed transparency of certificates and guaranteed, unequivocal revocation, achieved under NTTP-security, i.e., without requiring trust in any single CA, logger, or relying party. These guarantees hold even in the presence of arbitrary corruptions of these entities, assuming only a known bound (f ) of corrupt monitors (e.g., f = 8), with minimal performance impact. CTng also enables efficient certificate validation and preserves relying-party privacy, while providing scalable and efficient distribution of revocation updates. These properties significantly improve upon current PKI designs. In particular, while Certificate Transparency (CT) [35] , [36], [37] aims to eliminate single points of trust, the existing specification [36] still assumes benign loggers. Addressing this through log redundancy is possible, but rather inefficient, limiting deployed configurations to f ≤ 2. We present a security analysis and an evaluation of our opensource CTng prototype, showing that it is efficient and scalable under realistic deployment conditions. I. INTRODUCTION The Public Key Infrastructure (PKI) facilitates the secure use of public keys. PKI is critical for the security of open, distributed systems such as the Internet. Typically, a relying party obtains a public key and validates it using a certificate signed by a trusted Certificate Authority (CA). The PKI defines how certificates are issued and revoked (by the CAs) and validated (by relying parties). Most deployed PKIs follow the X.509 standard [8], [24]. X.509 certificates are used in protocols such as TLS, SSH, S/MIME, IPsec, and others. The most common application of PKI is to secure web and other forms of communication § The work was partially completed during the author's PhD studies at the
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- RHINE: Robust and High-performance Internet Naming with E2E AuthenticityHuayi Duan, Rubén Fischer, Jie Lou, Si Liu 等NSDI 2023 · 被引用 12 次
- SoK: Cryptographic Authenticated DictionariesHarjasleen Malvai, Francesca Falzon, Andrew Zitek-Estrada, Sarah Meiklejohn 等NDSS 2026 · 被引用 2 次
- Transparent Dictionaries from Polynomial CommitmentsHossein Hafezi, Alireza Shirzad, Benedikt Bünz, Joseph BonneauUSENIX Security 2026 · 被引用 1 次
- Accountability in Certificate Transparency and VariantsTimo Treitz, Robert KünnemannCCS 2026
它引用的顶会 Paper8
- Keeping Authorities "Honest or Bust" with Decentralized Witness CosigningEwa Syta, Iulia Tamas, Dylan Visher, David Isaac Wolinsky 等S&P 2016 · 被引用 285 次
- Narwhal and Tusk: a DAG-based mempool and efficient BFT consensusGeorge Danezis, Lefteris Kokoris-Kogias, Alberto Sonnino, Alexander SpiegelmanEuroSys 2022 · 被引用 259 次
- IKP: Turning a PKI Around with Decentralized Automated IncentivesStephanos Matsumoto, Raphael M. ReischukS&P 2017 · 被引用 168 次
- Catena: Efficient Non-equivocation via BitcoinAlin Tomescu, Srinivas DevadasS&P 2017 · 被引用 144 次
- DispersedLedger: High-Throughput Byzantine Consensus on Variable Bandwidth NetworksLei Yang, Seo Jin Park, Mohammad Alizadeh, Sreeram Kannan 等NSDI 2022 · 被引用 120 次
相关 Paper
- Does Certificate Transparency Break the Web? Measuring Adoption and Error RateEmily Stark, Ryan Sleevi, Rijad Muminovic, Devon O'Brien 等S&P 2019 · 被引用 44 次
- Pruning the Tree: Rethinking RPKI Architecture from the Ground upHaya Schulmann, Niklas VogelNDSS 2026 · 被引用 1 次
- On Re-engineering the X.509 PKI with Executable Specification for Better Implementation GuaranteesJoyanta Debnath, Sze Yiu Chau, Omar ChowdhuryCCS 2021 · 被引用 8 次
- On the Unnecessary Complexity of Names in X.509 and Their Impact on ImplementationsYuteng Sun, Joyanta Debnath, Wenzheng Hong, Omar Chowdhury 等FSE 2025
- CRLite: A Scalable System for Pushing All TLS Revocations to All BrowsersJames Larisch, David R. Choffnes, Dave Levin, Bruce M. Maggs 等S&P 2017 · 被引用 105 次
