F-PKI: Enabling Innovation and Trust Flexibility in the HTTPS Public-Key Infrastructure
Laurent Chuat, Cyrill Kr\"ahenb\"uhl, Prateek Mittal, Adrian Perrig

TL;DR
F-PKI enhances the HTTPS web PKI by introducing trust flexibility for clients and domain owners, enabling stronger security policies, supporting trust heterogeneity, and fostering innovation while maintaining backward compatibility.
Contribution
It introduces a novel trust flexibility mechanism in web PKI, allowing domain policies and client validation policies, which is a significant advancement over traditional uniform trust models.
Findings
Supports trust heterogeneity among parties.
Ensures verifiability of all certificates.
Prevents downgrade attacks.
Abstract
We present F-PKI, an enhancement to the HTTPS public-key infrastructure (or web PKI) that gives trust flexibility to both clients and domain owners, and enables certification authorities (CAs) to enforce stronger security measures. In today's web PKI, all CAs are equally trusted, and security is defined by the weakest link. We address this problem by introducing trust flexibility in two dimensions: with F-PKI, each domain owner can define a domain policy (specifying, for example, which CAs are authorized to issue certificates for their domain name) and each client can set or choose a validation policy based on trust levels. F-PKI thus supports a property that is sorely needed in today's Internet: trust heterogeneity. Different parties can express different trust preferences while still being able to verify all certificates. In contrast, today's web PKI only allows clients to fully…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
