Private Queries on Public Certificate Transparency Data
Vy-An Phan

TL;DR
This paper addresses privacy concerns in Certificate Transparency by proposing an oblivious file sharing system to enable secure, scalable, and anonymous queries without leaking user browsing data.
Contribution
It introduces a novel privacy-preserving approach for querying CT data using an oblivious file sharing system, enhancing user privacy and system scalability.
Findings
Proposes a scalable, privacy-preserving query system for CT data
Demonstrates strong anonymity properties in user queries
Improves upon existing CT validation privacy solutions
Abstract
Despite increasing advancements in today's information exchange infrastructure, the preservation of user data and privacy still remains a problem. Both insecure baselines and secure solutions leak user data. For example, Certificate Transparency (CT) promises significant security improvements to existing Public Key Infrastructure solutions that up-to-now have solely relied on the Certificate Authority hierarchy. CT provides a robust auditing layer and transparency solution to quickly detect such compromises, but introduces the requirement that client browsers interact with third-party servers when validating a site certificate. In the existing CT system, these requests leak information about each user's browsing habits to the hosting server. It is not a stretch to think that this valuable data could be collected and exploited, as corporations and governments have plenty of financial and…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsCryptography and Data Security · Privacy-Preserving Technologies in Data · Internet Traffic Analysis and Secure E-voting
