In Certificates We Trust -- Revisited

Florian Reimair, Peter Teufl, Bernd Prünster · 2015 IEEE Trustcom/BigDataSE/ISPA · 2015

Today's state-of-the-art workflow -- when encrypting data for one or more recipients -- requires for the sender to select the respective encryption keys. Naturally, it is crucial for data security to pick the correct keys with sufficient security levels. Yet, for selecting a key, the sender has to trust a recipient-chosen third party and therefore bears the hardly controllable risk of choosing a bad key. We propose to redistribute the tasks and require for a data sender to create an encryption key for himself and grant the recipient access to the key through authentication. The sender therefore can select the authentication methods, key strength, and key lifetime that suits his needs. In order to do this, we take advantage of the (semi-)centralized key storage solution CrySIL and add advanced policy enforcement options. We show the results of our prototypical implementation and present a discussion on the security of the system.

Read the paper · More papers on PaperTik