SoK: SCT Auditing in Certificate Transparency
Sarah Meiklejohn, Joe DeBlasio, Devon O'Brien, Chris Thompson, Kevin, Yeo, Emily Stark

TL;DR
This paper surveys privacy-preserving techniques for auditing certificate inclusion in Certificate Transparency logs, analyzing their effectiveness, efficiency, and deployment challenges to enhance secure and private web communication.
Contribution
It provides a comprehensive analysis of existing privacy-preserving SCT auditing methods, highlighting their limitations and guiding future research directions.
Findings
Many proposals have privacy limitations.
Current methods focus on client-log interaction, neglecting private reporting.
Significant challenges remain for practical deployment.
Abstract
The Web public key infrastructure is essential to providing secure communication on the Internet today, and certificate authorities play a crucial role in this ecosystem by issuing certificates. These authorities may misissue certificates or suffer misuse attacks, however, which has given rise to the Certificate Transparency (CT) project. The goal of CT is to store all issued certificates in public logs, which can then be checked for the presence of potentially misissued certificates. Thus, the requirement that a given certificate is indeed in one (or several) of these logs lies at the core of CT. In its current deployment, however, most individual clients do not check that the certificates they see are in logs, as requesting a proof of inclusion directly reveals the certificate and thus creates the clear potential for a violation of that client's privacy. In this paper, we explore the…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsCryptography and Data Security · Access Control and Trust · Internet Traffic Analysis and Secure E-voting
