STH Cross Logging

Benjamin Hof · 2017

A malicious Certificate Transparency (CT) log can offer a modified tree to a client in a attack. This document proposes to extend CT by submitting Signed Tree Heads (STH) into another log, run by a different operator. Auditors and monitors can use these cross logged STHs to detect split view attacks by the log.

Read the paper · More papers on PaperTik