详细信息

HTTPAS: active authentication against HTTPS man-in-the-middle attacks  ( SCI-EXPANDED收录 EI收录)  

文献类型:期刊文献

英文题名:HTTPAS: active authentication against HTTPS man-in-the-middle attacks

作者:Zhou, Peng[1];Gu, Xiaojing[2]

机构:[1]Shanghai Univ, Sch Mech Engn & Automat, Shanghai, Peoples R China;[2]East China Univ Sci & Technol, Sch Informat Sci & Engn, Shanghai, Peoples R China

年份:2016

卷号:10

期号:17

起止页码:2308

外文期刊名:IET COMMUNICATIONS

收录:;EI(收录号:20164803056809);WOS:【SCI-EXPANDED(收录号:WOS:000388498700007)】;

基金:This work was partially supported by the National Natural Science Foundation of China (Nos. 61502293, 61633016 and 61673255), the Shanghai Young Eastern Scholar Program, the Young Teachers' Training Program for Shanghai College & University, and the Shanghai Key Laboratory of Power Station Automation Technology.

语种:英文

外文关键词:transport protocols; hypermedia; cryptographic protocols; Internet; HTTPAS; active authentication architecture; HTTPS man-in-the-middle attacks; hypertext transfer protocol secure; pre-trusted certificate authorities; CAs; notary-based systems; pre-shared secrets; openSSL suite; Internet path diversity

摘要:Hypertext transfer protocol secure (HTTPS) relies on a group of pre-trusted certificate authorities (CAs) for authentication and hence can avoid man-in-the-middle attacks. However unfortunately, this authentication architecture can be completely subverted in case any one (usually the weakest one) of CAs has been compromised. To tackle this critical flaw, pioneer works such as notary-based systems and pre-shared secrets have been proposed. These state-of-the-art techniques can neither seek maximal protection from available CAs nor resist potential man-in-the-middle variants. In this study, the authors propose HTTPAS, a new HTTP Active Secure framework that can enhance the HTTPS authentication against man-in-the-middle attacks by actively utilising available CAs and exploiting Internet path diversity as much as possible. In particular, HTTPAS is designed with four practical solutions, each of which can make a unique trade-off among authentication capability, deployment difficulty and efficiency. They have implemented HTTPAS using the open secure sockets layer (SSL) suite, and also evaluated the implementation through experiments on several public certificate data sets and the Internet. Their results have successfully confirmed the authentication effectiveness of HTTPAS with only a few performance overheads and moderate deployment effort.

参考文献:

正在载入数据...

版权所有©华东理工大学 重庆维普资讯有限公司 渝B2-20050021-7 
渝公网安备 50019002500408号 违法和不良信息举报中心