照亮阴影:野外TLS客户端证书生态系统综合研究

Wei Xia, Mingxin Cui, Wen Wang, Yangyang Guan, Zhenzhen Li, Zhen Li, G. Xiong
{"title":"照亮阴影:野外TLS客户端证书生态系统综合研究","authors":"Wei Xia, Mingxin Cui, Wen Wang, Yangyang Guan, Zhenzhen Li, Zhen Li, G. Xiong","doi":"10.1109/ICT52184.2021.9511513","DOIUrl":null,"url":null,"abstract":"Client certificate authentication (CCA) is gaining greater significance, as more and more security-critical private activities such like e-bank and e-health are being conducted online, posing strong needs for mutual authentication. Unlike server certificates, active measurement of client certificates via probing techniques is infeasible since CCA is non-mandatory in the TLS protocol. Passive measurement is technically feasible but requires consistent access to large-scale Internet traffic to be comprehensive and convincing, which puts very high requirements on the research conditions. In this paper, we present a comprehensive study of the client certificate ecosystem, as the outcome of by far the largest passive measurement of client certificates in literature. As many as 97 million unique client certificates have been collected from the top-level academic network in China during six months. We analyze the actual use of CCA and classify the client certificates into three categories according to purposes: device authentication, user authentication, and application authentication. We discuss the security of client certificates with respect to the certificate attributes and make comparisons between client and server certificates. We also evaluate the risk of privacy leakage caused by client certificates, indicating the severity and the culprit. We hope our work would benefit the community by depicting an intuitive overview of the client certificate ecosystem and inspiring new thoughts on certificate usage in all kinds of scenarios.","PeriodicalId":142681,"journal":{"name":"2021 28th International Conference on Telecommunications (ICT)","volume":"22 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-06-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":"{\"title\":\"Illuminate the Shadow: A Comprehensive Study of TLS Client Certificate Ecosystem in the Wild\",\"authors\":\"Wei Xia, Mingxin Cui, Wen Wang, Yangyang Guan, Zhenzhen Li, Zhen Li, G. Xiong\",\"doi\":\"10.1109/ICT52184.2021.9511513\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Client certificate authentication (CCA) is gaining greater significance, as more and more security-critical private activities such like e-bank and e-health are being conducted online, posing strong needs for mutual authentication. Unlike server certificates, active measurement of client certificates via probing techniques is infeasible since CCA is non-mandatory in the TLS protocol. Passive measurement is technically feasible but requires consistent access to large-scale Internet traffic to be comprehensive and convincing, which puts very high requirements on the research conditions. In this paper, we present a comprehensive study of the client certificate ecosystem, as the outcome of by far the largest passive measurement of client certificates in literature. As many as 97 million unique client certificates have been collected from the top-level academic network in China during six months. We analyze the actual use of CCA and classify the client certificates into three categories according to purposes: device authentication, user authentication, and application authentication. We discuss the security of client certificates with respect to the certificate attributes and make comparisons between client and server certificates. We also evaluate the risk of privacy leakage caused by client certificates, indicating the severity and the culprit. We hope our work would benefit the community by depicting an intuitive overview of the client certificate ecosystem and inspiring new thoughts on certificate usage in all kinds of scenarios.\",\"PeriodicalId\":142681,\"journal\":{\"name\":\"2021 28th International Conference on Telecommunications (ICT)\",\"volume\":\"22 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2021-06-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"3\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2021 28th International Conference on Telecommunications (ICT)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ICT52184.2021.9511513\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2021 28th International Conference on Telecommunications (ICT)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICT52184.2021.9511513","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3

摘要

随着越来越多的对安全至关重要的私人活动(如电子银行和电子医疗)在网上进行,对相互认证提出了强烈的需求,客户端证书认证(CCA)变得越来越重要。与服务器证书不同,通过探测技术对客户端证书进行主动测量是不可行的,因为CCA在TLS协议中不是强制性的。被动测量在技术上是可行的,但需要对大规模互联网流量的一致接入才能做到全面可信,这对研究条件提出了很高的要求。在本文中,我们对客户端证书生态系统进行了全面研究,作为迄今为止文献中最大的客户端证书被动测量的结果。在六个月的时间里,从中国顶级学术网络中收集了多达9700万份独特的客户证书。我们分析了CCA的实际使用情况,并将客户端证书根据用途分为三类:设备认证、用户认证和应用程序认证。我们从证书属性的角度讨论客户端证书的安全性,并对客户端证书和服务器证书进行比较。我们还评估了客户端证书引起的隐私泄露风险,指出了严重程度和罪魁祸首。我们希望我们的工作能够对客户端证书生态系统进行直观的概述,并激发人们对各种场景中证书使用的新思考,从而使社区受益。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
Illuminate the Shadow: A Comprehensive Study of TLS Client Certificate Ecosystem in the Wild
Client certificate authentication (CCA) is gaining greater significance, as more and more security-critical private activities such like e-bank and e-health are being conducted online, posing strong needs for mutual authentication. Unlike server certificates, active measurement of client certificates via probing techniques is infeasible since CCA is non-mandatory in the TLS protocol. Passive measurement is technically feasible but requires consistent access to large-scale Internet traffic to be comprehensive and convincing, which puts very high requirements on the research conditions. In this paper, we present a comprehensive study of the client certificate ecosystem, as the outcome of by far the largest passive measurement of client certificates in literature. As many as 97 million unique client certificates have been collected from the top-level academic network in China during six months. We analyze the actual use of CCA and classify the client certificates into three categories according to purposes: device authentication, user authentication, and application authentication. We discuss the security of client certificates with respect to the certificate attributes and make comparisons between client and server certificates. We also evaluate the risk of privacy leakage caused by client certificates, indicating the severity and the culprit. We hope our work would benefit the community by depicting an intuitive overview of the client certificate ecosystem and inspiring new thoughts on certificate usage in all kinds of scenarios.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Optimization of non-binary LDPC coded massive MIMO systems with partial mapping and EP detection A Fast Identification Method of Shortwave Radio Stations Based on Sparse Component Analysis Learning-Based Fast Decision for Task Execution in Next Generation Wireless Networks Enabling URLLC under $\kappa-\mu$ Shadowed Fading A DNS Security Policy for Timely Detection of Malicious Modification on Webpages
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1