CRLite: A Scalable System for Pushing All TLS Revocations to All Browsers
James Larisch, David R. Choffnes, Dave Levin, Bruce M. Maggs, Alan Mislove, Christo Wilson
摘要
Currently, no major browser fully checks for TLS/SSL certificate revocations. This is largely due to the fact that the deployed mechanisms for disseminating revocations (CRLs, OCSP, OCSP Stapling, CRLSet, and OneCRL) are each either incomplete, insecure, inefficient, slow to update, not private, or some combination thereof. In this paper, we present CRLite, an efficient and easily-deployable system for proactively pushing all TLS certificate revocations to browsers. CRLite servers aggregate revocation information for all known, valid TLS certificates on the web, and store them in a space-efficient filter cascade data structure. Browsers periodically download and use this data to check for revocations of observed certificates in realtime. CRLite does not require any additional trust beyond the existing PKI, and it allows clients to adopt a fail-closed security posture even in the face of network errors or attacks that make revocation information temporarily unavailable. We present a prototype of CRLite that processes TLS certificates gathered by Rapid7, the University of Michigan, and Google's Certificate Transparency on the server-side, with a Firefox extension on the client-side. Comparing CRLite to an idealized browser that performs correct CRL/OCSP checking, we show that CRLite reduces latency and eliminates privacy concerns. Moreover, CRLite has low bandwidth costs: it can represent all certificates with an initial download of 10 MB (less than 1 byte per revocation) followed by daily updates of 580 KB on average. Taken together, our results demonstrate that complete TLS/SSL revocation checking is within reach for all clients. Recent measurement studies demonstrate that revocation is prevalent in the web's PKI [49] . More than 99% of valid certificates available on the web contain a reachable CRL URL, while 95% include a reachable OCSP responder. Liu et al. observe that 8% of all valid certificates are revoked (6% if we focus just on valid EV certificates) [49] , with the bulk of these revocations occurring due to Heartbleed [76], [19] .
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper19
- Let's Encrypt: An Automated Certificate Authority to Encrypt the Entire WebJosh Aas, Richard Barnes, Benton Case, Zakir Durumeric 等CCS 2019 · 被引用 138 次
- Private Blocklist Lookups with ChecklistDmitry Kogan, Henry Corrigan-GibbsUSENIX Security 2021 · 被引用 104 次
- Cloud Strife: Mitigating the Security Risks of Domain-Validated CertificatesKevin Borgolte, Tobias Fiebig, Shuang Hao, Christopher Kruegel 等NDSS 2018 · 被引用 63 次
- Vacuum Filters: More Space-Efficient and Faster Replacement for Bloom and Cuckoo FiltersMinmei Wang, Mingxun Zhou, Shouqian Shi, Chen QianVLDB 2020 · 被引用 58 次
- The ties that un-bind: decoupling IP from web services and sockets for robust addressing agility at CDN-scaleMarwan Fayed, Lorenz Bauer, Vasileios Giotsas, Sami Kerola 等SIGCOMM 2021 · 被引用 23 次
它引用的顶会 Paper4
- Keeping Authorities "Honest or Bust" with Decentralized Witness CosigningEwa Syta, Iulia Tamas, Dylan Visher, David Isaac Wolinsky 等S&P 2016 · 被引用 285 次
- Measurement and Analysis of Private Key Sharing in the HTTPS EcosystemFrank Cangialosi, Taejoong Chung, David R. Choffnes, Dave Levin 等CCS 2016 · 被引用 89 次
- Cinderella: Turning Shabby X.509 Certificates into Elegant Anonymous Credentials with the Magic of Verifiable ComputationAntoine Delignat-Lavaud, Cédric Fournet, Markulf Kohlweiss, Bryan ParnoS&P 2016 · 被引用 83 次
- Transparency Overlays and ApplicationsMelissa Chase, Sarah MeiklejohnCCS 2016 · 被引用 58 次
相关 Paper
- Clubcards for the WebPKI: Smaller Certificate Revocation Tests in Theory and PracticeJohn M. SchanckS&P 2025
- Does Certificate Transparency Break the Web? Measuring Adoption and Error RateEmily Stark, Ryan Sleevi, Rijad Muminovic, Devon O'Brien 等S&P 2019 · 被引用 44 次
- AccuRevoke: Enhancing Certificate Revocation with Distributed Cryptographic AccumulatorsMunshi Rejwan Ala Muid, Taejoong Chung, Thang HoangS&P 2025
- CTng: Secure Certificate and Revocation TransparencyJie Kong, James Damon, Hemi Leibowitz, Ewa Syta 等NDSS 2026 · 被引用 5 次
- Reliable and Decentralized Certificate Revocation via DNS: The Case for RevDNSTaejoong Chung, Dave Levin, Protick BhowmickSIGCOMM 2025 · 被引用 2 次
