A socio-technical understanding of TLS certificate validation

3Citations
Citations of this article
8Readers
Mendeley users who have this article in their library.

This article is free to access.

Abstract

To authenticate a web server,modern browsers check whether a TLS certificate is valid. This check is socio-technical because, when the technical validation fails, it may request the user to decide, intertwining the usual technical issues with social elements, such as trust and cultural values. Hence the need for a methodology aimed at a socio-technical understanding of TLS certificate validation. This aim is demanding not only due to user participation but also because browsers behave differently. An innovative methodology is outlined and demonstrated on the four marketleader browsers, Chrome, Internet Explorer, Firefox and Opera Mini. It involves modelling in UML the multi-layered interactions among servers, browsers, and users and then translating them into a formal language amenable to model checking socio-technical security properties.

Cite

CITATION STYLE

APA

Bella, G., Giustolisi, R., & Lenzini, G. (2013). A socio-technical understanding of TLS certificate validation. In IFIP Advances in Information and Communication Technology (Vol. 401, pp. 281–288). Springer New York LLC. https://doi.org/10.1007/978-3-642-38323-6_23

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free