Logo del repository
  1. Home
 
Opzioni

A Zero Trust Data-Driven Perspective on PKI Root Stores

Farina, Mauro
•
Ravalico, Damiano
•
Trevisan, Martino
•
Bartoli, Alberto
2025
  • journal article

Periodico
IEEE JOURNAL ON SELECTED AREAS IN COMMUNICATIONS
Abstract
Security and privacy on the Internet rely on the Public Key Infrastructure (PKI), which is based on unlimited trust in a set of predefined certification authorities included in the users' root stores. However, the architecture of the PKI is no longer appropriate for the current threat landscape and security principles. Specifically, the implicit and permanent trust given to certification authorities collides with the rising zero trust approach, a cyber-security model that mandates that trust must never be granted implicitly or permanently to any entity. This work offers a zero trust perspective on the PKI and root store composition. Using navigation datasets collected from users' browsers and passive monitors, we analyze their actual needs and identify the portion of root stores that are useful for their activity. We propose several zero trust policies to manage root stores that shrink the large perimeter of trust allowed by commercial root stores. Our experiments show that less than half of the root certificates included in the Mozilla root store are indeed used for navigation, while only 14 cover 99% of the traffic of our users. Moreover, implementing such policies requires little effort for a company, providing a practical way for managing root stores with up-to-date security principles.
DOI
10.1109/jsac.2025.3560006
WOS
WOS:001499693800001
Archivio
https://hdl.handle.net/11368/3110664
info:eu-repo/semantics/altIdentifier/scopus/2-s2.0-105002769522
https://ieeexplore.ieee.org/document/10963977
Diritti
closed access
license:copyright editore
license uri:iris.pri02
FVG url
https://arts.units.it/request-item?handle=11368/3110664
Soggetti
  • Certification Authori...

  • HTTPS

  • Internet Measurement

  • PKI

  • Zero Trust

google-scholar
Get Involved!
  • Source Code
  • Documentation
  • Slack Channel
Make it your own

DSpace-CRIS can be extensively configured to meet your needs. Decide which information need to be collected and available with fine-grained security. Start updating the theme to match your nstitution's web identity.

Need professional help?

The original creators of DSpace-CRIS at 4Science can take your project to the next level, get in touch!

Realizzato con Software DSpace-CRIS - Estensione mantenuta e ottimizzata da 4Science

  • Impostazioni dei cookie
  • Informativa sulla privacy
  • Accordo con l'utente finale
  • Invia il tuo Feedback