• DocumentCode
    1782814
  • Title

    Ubiquitous support of multi path probing: Preventing man in the middle attacks on Internet communication

  • Author

    Braun, Johannes

  • Author_Institution
    Tech. Univ. Darmstadt, Darmstadt, Germany
  • fYear
    2014
  • fDate
    29-31 Oct. 2014
  • Firstpage
    510
  • Lastpage
    511
  • Abstract
    Digital certificates issued by certification authorities (CAs) which are part of the Web Public Key Infrastructure (Web PKI) are the indispensable basis for secure communication on the Internet. The certificates are used in TLS to authenticate web servers. However, as past incidents have shown, CA failures and the issuance of malicious certificates threatens the security of communication, as it allows for man in the middle attacks (MitM) and server impersonation. All known mitigations so far are only niche solutions having their own weaknesses and problems which prevented a wide deployment. Thus, additional methods must be natively supported by common web servers to mitigate threats imposed by CA failures. We propose to integrate multi path probing of certificates as a fundamental mechanism into the web infrastructure. This enables the reconfirmation of certificates whenever their authenticity is in doubt. We describe how this can be realized with minor efforts and without infrastructural changes, while the overhead arising from these reconfirmations can be kept at a small rate.
  • Keywords
    Internet; digital signatures; public key cryptography; ubiquitous computing; CA; Internet communication; MitM; Web PKI; Web public key infrastructure; Web server authentication; certification authorities; digital certificates; man in the middle attacks; multipath probing; ubiquitous support; Browsers; Privacy; Public key; Web servers;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Communications and Network Security (CNS), 2014 IEEE Conference on
  • Conference_Location
    San Francisco, CA
  • Type

    conf

  • DOI
    10.1109/CNS.2014.6997529
  • Filename
    6997529