Matheus Aranha, Diogo Pereira, Artur Ziviani, F. Borges
{"title":"ANÁLISE DE CERTIFICADOS DIGITAIS EM DOMÍNIOS BRASILEIROS","authors":"Matheus Aranha, Diogo Pereira, Artur Ziviani, F. Borges","doi":"10.17648/WRAC-2018-97120","DOIUrl":null,"url":null,"abstract":". We introduce a security requirement and its security assessment for an Internet protocol. Specifically, this work presents a verification of the RSA keys of digital certificates present in the Brazilian domains that use the HTTPS protocol. Such verification depends on randomness in the generation of prime numbers. We use Graph Theory concepts to get three results based on the data we collected from hundreds of millions of domains. In the first result, we performed an iteration on the certificates, generating hundreds of millions of veri-fications. Luckily, we show that HTTPS is safe from this attack. In the second, we show that many domains share the same cryptographic key. In the third, we show that only 1% of the certification authorities are relevant.","PeriodicalId":188855,"journal":{"name":"Estudos (Inter) Multidisciplinares nas Engenharias","volume":"42 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2019-10-09","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Estudos (Inter) Multidisciplinares nas Engenharias","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.17648/WRAC-2018-97120","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1
Abstract
. We introduce a security requirement and its security assessment for an Internet protocol. Specifically, this work presents a verification of the RSA keys of digital certificates present in the Brazilian domains that use the HTTPS protocol. Such verification depends on randomness in the generation of prime numbers. We use Graph Theory concepts to get three results based on the data we collected from hundreds of millions of domains. In the first result, we performed an iteration on the certificates, generating hundreds of millions of veri-fications. Luckily, we show that HTTPS is safe from this attack. In the second, we show that many domains share the same cryptographic key. In the third, we show that only 1% of the certification authorities are relevant.