A Socio-technical Understanding of TLS Certificate Validation

Interdisciplinary Research Group in Socio-technical Cybersecurity

A Socio-technical Understanding of TLS Certificate Validation

Giampaolo Bella, Rosario Giustolisi, Gabriele Lenzini
Abstract:
To authenticate a web server, modern browsers check whether a TLS certificate is valid. This check is socio-technical because, when the technical validation fails, it may request the user to decide, intertwining the usual technical issues with social elements, such as trust and cultural values. Hence the need for a methodology aimed at a socio-technical understanding of TLS certificate validation. This aim is demanding not only due to user participation but also because browsers behave differently. An innovative methodology is outlined and demonstrated on the four market-leader browsers, Chrome, Internet Explorer, Firefox and Opera Mini. It involves modelling in UML the multi-layered interactions among servers, browsers, and users and then translating them into a formal language amenable to model checking socio-technical security properties.
Authors:
Giampaolo Bella, Rosario Giustolisi, Gabriele Lenzini
Publication date:
2013
Published in:
IFIP Advances in Information and Communication Technology
Reference:
Bella, G., Giustolisi, R., & Lenzini, G. (2013, June). A Socio-technical Understanding of TLS Certificate Validation. In IFIP International Conference on Trust Management (pp. 281-288). Springer, Berlin, Heidelberg.

Get in touch with us

SnT – Interdisciplinary Centre for Security, Reliability and Trust
Maison du Nombre, 6, avenue de la Fonte L-4364 Esch-sur-Alzette
info-irisc-lab@uni.lu