vix.ing · top · new · best · stats

Autonomous collision attack on OCSP services

2016/09/10 by Ken Ivanov, Ivanov, Ken
Computer Science · #68M12 #Advanced Malware Detection Techniques #Cryptographic Implementations and Security #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #Security and Verification in Computing #cs.CR #msc:68M12

paper · pdf · doi:10.48550/arxiv.1609.03047

16 pages, 4 figures

arxiv created 2016/09/10 · openalex publication_date 2016/09/10 · arxiv updated 2016/09/13 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/28

Abstract

The paper describes two important design flaws in Online Certificate Status Protocol (OCSP), a protocol widely used in PKI environments for managing digital certificates' credibility in real time. The flaws significantly reduce the security capabilities of the protocol, and can be exploited by a malicious third party to generate forged signed certificate statuses and, in the worst scenario, forged certificates. Description of the flaws, along with expected exploitation routes, consequences for consuming application layer protocols, and proposed countermeasures, is given.

Related