A Socio-technical Understanding of TLS Certificate Validation - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2013

A Socio-technical Understanding of TLS Certificate Validation

Résumé

To authenticate a web server, modern browsers check whether a TLS certificate is valid. This check is socio-technical because, when the technical validation fails, it may request the user to decide, intertwining the usual technical issues with social elements, such as trust and cultural values. Hence the need for a methodology aimed at a socio-technical understanding of TLS certificate validation. This aim is demanding not only due to user participation but also because browsers behave differently. An innovative methodology is outlined and demonstrated on the four market-leader browsers, Chrome, Internet Explorer, Firefox and Opera Mini. It involves modelling in UML the multi-layered interactions among servers, browsers, and users and then translating them into a formal language amenable to model checking socio-technical security properties.
Fichier principal
Vignette du fichier
978-3-642-38323-6_23_Chapter.pdf (328.46 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-01468204 , version 1 (15-02-2017)

Licence

Paternité

Identifiants

Citer

Giampaolo Bella, Rosario Giustolisi, Gabriele Lenzini. A Socio-technical Understanding of TLS Certificate Validation. 7th Trust Management (TM), Jun 2013, Malaga, Spain. pp.281-288, ⟨10.1007/978-3-642-38323-6_23⟩. ⟨hal-01468204⟩
110 Consultations
151 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More