Accountability in Certificate Transparency and Variants

📅 2026-09-10
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
本文通过Dolev-Yao模型分析了证书透明度(CT)及其变体如何在假设日志诚实的情况下提供责任性,并探讨了SCT审计和八卦扩展对这一假设的影响。
📝 Abstract
Certificate Transparency (CT) aims to reduce the trust required in Certificate Authorities (CAs) within the TLS certificate ecosystem. It is supported by all major browsers. The protocol obliges all CAs to record the certificates they issue in a public log, which itself is monitored for compliance and consistency by third parties. Given this complex set of checks between the four roles-CA, loggers, monitor but also the end user's client-it is very hard to provide a precise account of how CT eliminates trust assumptions in exchange for complex infrastructure. Analyses both in the Dolev-Yao paradigm and the computational paradigm only regard a very simplified model and feature definitions adapted specifically to CAs, essentially capturing design features rather than the target property. The present paper posits accountability as the main goal of CT and presents a thorough analysis in the Dolev-Yao model. We start with the vanilla PKI and, step by step, move to CT, finally analyzing proposed extensions for SCT Auditing and Gossiping. We show that plain CT relies on an honest log, but provides accountability under this assumption. Furthermore, we show that the SCT Auditing extension can eliminate this assumption, while the Gossiping extension cannot.
Problem

Research questions and friction points this paper is trying to address.

Certificate Transparency
Accountability
Trust Assumptions
Dolev-Yao Model
SCT Auditing
Innovation

Methods, ideas, or system contributions that make the work stand out.

Accountability
Certificate Transparency
Dolev-Yao Model
SCT Auditing
Gossiping
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
T
Timo Treitz
Saarland University
R
Robert Künnemann
CISPA Helmholtz Center for Information Security