Skip to main content

2024 | OriginalPaper | Buchkapitel

Enhancing the ACME Protocol to Automate the Management of All X.509 Web Certificates

verfasst von : David A. Cordova Morales, Ahmad Samer Wazan, David W. Chadwick, Romain Laborde, April Rains Reyes Maramara, Kalil Cabral

Erschienen in: ICT Systems Security and Privacy Protection

Verlag: Springer Nature Switzerland

Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.

search-config
loading …

Abstract

X.509 Public Key Infrastructures (PKIs) are widely used for managing X.509 Public Key Certificates (PKCs) to allow for secure communications and authentication on the Internet. PKCs are issued by a trusted third-party Certification Authority (CA), which is responsible for verifying the certificate requester’s information. Recent developments in web PKI show a high proliferation of Domain Validated (DV) certificates but a decline in Extended Validated (EV) certificates, indicating poor authentication of the entities behind web services. The ACME protocol facilitates the deployment of Web Certificates by automating their management. However, it is only limited to DV certificates. This paper proposes an enhancement to the ACME protocol for automating all types of Web X.509 PKCs by using W3C Verifiable Credentials (VCs) to assert a requester’s claims. We argue that any CA’s requirements for issuing a PKC can be expressed as a set of VCs, returned in a Verifiable Presentation (VP). We propose a generic communication workflow to request and present VPs, and provide proof-of-concept of the viability of our approach.

Sie haben noch keine Lizenz? Dann Informieren Sie sich jetzt über unsere Produkte:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Fußnoten
3
Identifiers for EV and OV certificates include also organization name, address, business category, etc.
 
Literatur
1.
Zurück zum Zitat Aas, J., et al.: Let’s encrypt: an automated certificate authority to encrypt the entire web. In: Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security, pp. 2473–2487 (2019) Aas, J., et al.: Let’s encrypt: an automated certificate authority to encrypt the entire web. In: Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security, pp. 2473–2487 (2019)
2.
Zurück zum Zitat Barnes, R., Hoffman-Andrews, J., McCarney, D., Kasten, J.: Automatic certificate management environment (ACME). Technical report (2019) Barnes, R., Hoffman-Andrews, J., McCarney, D., Kasten, J.: Automatic certificate management environment (ACME). Technical report (2019)
5.
Zurück zum Zitat Chadwick, K.N., Vercammen, J.: OpenID for verifiable credentials (2022) Chadwick, K.N., Vercammen, J.: OpenID for verifiable credentials (2022)
10.
Zurück zum Zitat Jones, M., Bradley, J., Sakimura, N.: Json web token (JWT). Technical report (2015) Jones, M., Bradley, J., Sakimura, N.: Json web token (JWT). Technical report (2015)
11.
Zurück zum Zitat Krombholz, K., Mayer, W., Schmiedecker, M., Weippl, E.: “i have no idea what i’m doing”-on the usability of deploying HTTPS (2017) Krombholz, K., Mayer, W., Schmiedecker, M., Weippl, E.: “i have no idea what i’m doing”-on the usability of deploying HTTPS (2017)
12.
Zurück zum Zitat Matthew, B., Jonathan, S., Ziegler, A.C., Philip, K., Wallach, D.S., Alex, H.J.: On the usability of https deployment. In: Proceedings of the 2019 CHI Conference on Human Factors in Computing Systems, pp. 1–10 (2019) Matthew, B., Jonathan, S., Ziegler, A.C., Philip, K., Wallach, D.S., Alex, H.J.: On the usability of https deployment. In: Proceedings of the 2019 CHI Conference on Human Factors in Computing Systems, pp. 1–10 (2019)
13.
Zurück zum Zitat Sedlmeir, J., Smethurst, R., Rieger, A., Fridgen, G.: Digital identities and verifiable credentials. Bus. Inf. Syst. Eng. 63(5), 603–613 (2021)CrossRef Sedlmeir, J., Smethurst, R., Rieger, A., Fridgen, G.: Digital identities and verifiable credentials. Bus. Inf. Syst. Eng. 63(5), 603–613 (2021)CrossRef
15.
Zurück zum Zitat Thompson, C., Shelton, M., Stark, E., Walker, M., Schechter, E., Felt, A.P.: The web’s identity crisis: understanding the effectiveness of website identity indicators, pp. 1715–1732 (2019) Thompson, C., Shelton, M., Stark, E., Walker, M., Schechter, E., Felt, A.P.: The web’s identity crisis: understanding the effectiveness of website identity indicators, pp. 1715–1732 (2019)
20.
Zurück zum Zitat Wazan, A.S., Laborde, R., Chadwick, D.W., Barrere, F., Benzekri, A.: TLS connection validation by web browsers: why do web browsers still not agree? In: 2017 IEEE 41st Annual Computer Software and Applications Conference (COMPSAC), vol. 1, pp. 665–674. IEEE (2017) Wazan, A.S., Laborde, R., Chadwick, D.W., Barrere, F., Benzekri, A.: TLS connection validation by web browsers: why do web browsers still not agree? In: 2017 IEEE 41st Annual Computer Software and Applications Conference (COMPSAC), vol. 1, pp. 665–674. IEEE (2017)
21.
Zurück zum Zitat Wazan, A.S., et al.: On the validation of web X.509 certificates by TLS interception products. IEEE Trans. Dependable Secure Comput. 19(1), 227–242 (2020)CrossRef Wazan, A.S., et al.: On the validation of web X.509 certificates by TLS interception products. IEEE Trans. Dependable Secure Comput. 19(1), 227–242 (2020)CrossRef
Metadaten
Titel
Enhancing the ACME Protocol to Automate the Management of All X.509 Web Certificates
verfasst von
David A. Cordova Morales
Ahmad Samer Wazan
David W. Chadwick
Romain Laborde
April Rains Reyes Maramara
Kalil Cabral
Copyright-Jahr
2024
DOI
https://doi.org/10.1007/978-3-031-56326-3_19

Premium Partner