Certification with Multiple Signatures
Xinli Wang, Yan Zhi Bai, Lihui Hu · 2015
Certificate Authority (CA) is a single point of failure in the design of Public Key Infrastructure (PKI). A single compromised CA breaks the entire infrastructure. The disclosed CA key can be used by adversaries to issue rogue certificates for any domains without the consent of the domain owners. These rogue certificates have been used in Man-in-the-Middle (MitM) attacks. Studies have been conducted to prevent and reduce the damages of breached CAs and rogue certificates in different ways. However, few have a mechanism to fully and efficiently verify whether a CA or a certificate can be trusted or not. There is a need to develop new methods to ensure certificates with a high level of trustworthy in order for the PKI to be more resistant to compromised CAs and rogue certificates.