Authenticating HTTPS Connection without Relying on Certification Authorities
Sifan Waktole Dadi, Ahmad Samer Wazan, Imran Taj · 2024
Internet security heavily depends on Transport Layer Security (TLS) and X.509 certificates. A Certification Authority (CA) issues these certificates so users can safely connect to verified websites. However, CA-based authentication mechanisms depend on CA's behavior or on the integrity of their systems. Furthermore, traditional methods for revoking certificates, like the Online Certificate Status Protocol (OCSP) and Certificate Revocation Lists (CRL), present unsolvable challenges. While CRL updates are inefficient, OCSP poses privacy concerns and causes delays. Our goal is to move trust from potentially unreliable CAs to a secure, easy-to-use system that uses the DNS over HTTPS (DoH) servers, which are already deployed with most web browsers. With our approach, trusted DoH servers can handle simultaneously domain name resolution and public key authentication, thereby reducing the dependency on CAs. With regards to the revocation, our approach enables public key owners to tailor their key lifetimes, thus minimizing the need for conventional revocation. A proof of concept is implemented and presented to demonstrate the effectiveness and the feasibility of our approach.