论文标题
SmartCert:使用智能合约重新设计数字证书
SmartCert: Redesigning Digital Certificates with Smart Contracts
论文作者
论文摘要
运输层安全性(TLS)协议及其公钥基础架构(PKI)在Internet中广泛使用,以实现安全的通信。通过受信任的认证机构(CAS)验证域名是发行数字证书的关键步骤,但不幸的是,此过程提供了较差的安全级别。在这项工作中,我们提出了SmartCert,这是一种基于智能合约以改善数字证书的新方法。 SmartCert中的证书传达了有关其验证状态的详细信息,该信息正在不断变化,但仅在指定的智能合约代码和单个域策略方面。 CAS签发和更新证书持续负责,其措施是透明的,并由代码监控。我们介绍了SmartCert的实施和评估,并讨论其可部署性。
The Transport Layer Security (TLS) protocol and its public-key infrastructure (PKI) are widely used in the Internet to achieve secure communication. Validating domain ownership by trusted certification authorities (CAs) is a critical step in issuing digital certificates, but unfortunately, this process provides a poor security level. In this work, we present SmartCert, a novel approach based on smart contracts to improve digital certificates. A certificate in SmartCert conveys detailed information about its validation state which is constantly changing but only with respect to the specified smart contract code and individual domain policies. CAs issuing and updating certificates are kept accountable and their actions are transparent and monitored by the code. We present the implementation and evaluation of SmartCert, and discuss its deployability.