{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,17]],"date-time":"2026-06-17T13:01:57Z","timestamp":1781701317037,"version":"3.54.5"},"reference-count":71,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"2","license":[{"start":{"date-parts":[[2025,4,1]],"date-time":"2025-04-01T00:00:00Z","timestamp":1743465600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,4,1]],"date-time":"2025-04-01T00:00:00Z","timestamp":1743465600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,4,1]],"date-time":"2025-04-01T00:00:00Z","timestamp":1743465600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Netw."],"published-print":{"date-parts":[[2025,4]]},"DOI":"10.1109\/tnet.2024.3495617","type":"journal-article","created":{"date-parts":[[2024,11,19]],"date-time":"2024-11-19T18:50:42Z","timestamp":1732042242000},"page":"595-611","source":"Crossref","is-referenced-by-count":2,"title":["Measuring and Characterizing Propagation of Reuse RSA Certificates and Keys Across PKI Ecosystem"],"prefix":"10.1109","volume":"33","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-7206-8614","authenticated-orcid":false,"given":"Fatemeh","family":"Nezhadian","sequence":"first","affiliation":[{"name":"Department of Computer Science, University of Saskatchewan, Saskatoon, SK, Canada"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6316-7789","authenticated-orcid":false,"given":"Enrico","family":"Branca","sequence":"additional","affiliation":[{"name":"Department of Computer Science, University of Saskatchewan, Saskatoon, SK, Canada"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Anna","family":"Barzolevskaia","sequence":"additional","affiliation":[{"name":"Department of Computer Science, University of Saskatchewan, Saskatoon, SK, Canada"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Andrei","family":"Natadze","sequence":"additional","affiliation":[{"name":"Department of Computer Science, University of Saskatchewan, Saskatoon, SK, Canada"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1923-319X","authenticated-orcid":false,"given":"Natalia","family":"Stakhanova","sequence":"additional","affiliation":[{"name":"Department of Computer Science, University of Saskatchewan, Saskatoon, SK, Canada"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","volume-title":"Github Security Update: Revoking Weakly-Generated SSH Keys","author":"Hanley","year":"2021"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3133969"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1145\/2068816.2068856"},{"key":"ref4","first-page":"205","article-title":"Mining your PS and QS: Detection of widespread weak keys in network devices","volume-title":"Proc. 21st USENIX Secur. Symp. (USENIX Secur.)","author":"Heninger"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2014.42"},{"key":"ref6","first-page":"95","article-title":"A large-scale analysis of the security of embedded firmwares","volume-title":"Proc. 23rd USENIX Secur. Symp.","author":"Costin"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516693"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1145\/2663716.2663755"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243783"},{"key":"ref10","first-page":"893","article-title":"The million-key question\u2014Investigating the origins of RSA public keys","volume-title":"Proc. 25th USENIX Secur. Symp. (USENIX Secur.)","author":"Svenda"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/3196494.3196538"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/NOMS.2014.6838249"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-59013-0_25"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-90019-9_19"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978301"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1145\/2815675.2815685"},{"key":"ref17","doi-asserted-by":"crossref","DOI":"10.17487\/RFC8446","volume-title":"The Transport Layer Security (TLS) Protocol Version 1.3","author":"Rescorla","year":"2018"},{"key":"ref18","volume-title":"The Secure Shell (SSH) Transport Layer Protocol","author":"Lonvick","year":"2006"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.17487\/rfc5280"},{"key":"ref20","doi-asserted-by":"crossref","DOI":"10.17487\/rfc4572","volume-title":"Connection-Oriented Media Transport Over The Transport Layer Security (TLS) Protocol in The Session Description Protocol (SDP)","author":"Lennox","year":"2006"},{"key":"ref21","volume-title":"PKCS #1: RSA Cryptography Specifications Version 2.0","author":"Kaliski","year":"1998"},{"key":"ref22","volume-title":"Digital Signature Standard (DSS)","year":"2023"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23055"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1145\/3487552.3487830"},{"key":"ref25","first-page":"252","article-title":"Missed Opportunities: Measuring the untapped TLS support in the industrial Internet of Things","volume-title":"Proc. ACM Asia Conf. Comput. Commun. Secur.","author":"Dahlmanns"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1145\/2987443.2987454"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-70972-7_30"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484569"},{"key":"ref29","first-page":"64","article-title":"Ron was wrong, whit is right","author":"Lenstra","year":"2012","journal-title":"IACR Cryptol. ePrint Arch."},{"key":"ref30","first-page":"1185","article-title":"On the security of TLS 1.3 and QUIC against weaknesses in PKCS#1 v1.5 encryption","volume-title":"Proc. 22nd ACM SIGSAC Conf. Comput. Commun. Secur. (CCS)","author":"Jager"},{"key":"ref31","first-page":"567","article-title":"The dangers of key reuse: Practical attacks on IPsec IKE","volume-title":"Proc. 27th USENIX Secur. Symp. (USENIX Secur.)","author":"Felsch"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3133958"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-49187-0_12"},{"key":"ref34","article-title":"AndroTracker: Creator information based Android malware classification system","volume-title":"Proc. 15th Int. Workshop Inf. Secur. Appl. (Creator)","volume":"8909","author":"Kang"},{"key":"ref35","doi-asserted-by":"crossref","DOI":"10.17487\/rfc6962","volume-title":"Certificate Transparency","author":"Laurie","year":"2013"},{"key":"ref36","volume-title":"Sovereign Key Cryptography for Internet Domains","author":"Eckersley"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1145\/2488388.2488448"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.17"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2016.2601610"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-11039-0_11"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1145\/1644893.1644896"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1145\/2987443.2987486"},{"key":"ref43","first-page":"605","article-title":"ZMap: Fast internet-wide scanning and its security applications","volume-title":"Proc. 22nd USENIX Secur. Symp. (USENIX Secur.)","author":"Durumeric"},{"key":"ref44","volume-title":"SSH-Keyscan(1)"},{"key":"ref45","volume-title":"Rapid7 Sonar SSL\/TLS Datasets"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2016.11"},{"key":"ref47","volume-title":"VX-UNDERGROUND APT Information"},{"key":"ref48","volume-title":"VirusShare"},{"key":"ref49","volume-title":"PHP 8.4: OpenSSL: Minimum Required OpenSSL Version Increased To 1.1.1"},{"key":"ref50","volume-title":"PKCS #1: RSA Cryptography Specifications Version 2.2","author":"Moriarty","year":"8017"},{"key":"ref51","volume-title":"Object Identifiers (AD DS)","year":"2019"},{"key":"ref52","volume-title":"Microsoft Object Identifiers","author":"Durumeric","year":"2012"},{"key":"ref53","volume-title":"Sigtool","author":"Lee"},{"key":"ref54","article-title":"Recommendation for key management: Part 3","author":"Barker","year":"2015"},{"key":"ref55","doi-asserted-by":"crossref","DOI":"10.6028\/NIST.SP.800-56Br2","article-title":"Recommendation for pair-wise key establishment using integer factorization cryptography","author":"Barker","year":"2019"},{"key":"ref56","article-title":"Recommendation for key management: Part 1","author":"Barker","year":"2020"},{"key":"ref57","doi-asserted-by":"crossref","DOI":"10.17487\/rfc2818","volume-title":"HTTP Over TLS","author":"Rescorla","year":"2000"},{"key":"ref58","volume-title":"Baseline Requirements for the Issuance and Management of Publicly-Trusted Certificates","year":"2013"},{"key":"ref59","volume-title":"Securing Web Transactions TLS Server Certificate Management","year":"2020"},{"key":"ref60","volume-title":"Abusing Code Signing for Profit","year":"2019"},{"key":"ref61","volume-title":"Algorithms and Identifiers for the Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile","author":"Housley","year":"3279"},{"key":"ref62","volume-title":"Research Results on SHA-1 Collisions","year":"2017"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-03356-8_4"},{"key":"ref64","volume-title":"MD5 Vulnerable to Collision Attacks","author":"Dougherty","year":"2008"},{"key":"ref65","volume-title":"MD2 to Historic Status","author":"Turner","year":"6149"},{"key":"ref66","volume-title":"Using the GOST R 34.10-94, GOST R 34.10-2001, and GOST R 34.11-94 Algorithms With the Internet X.509 Public Key Infrastructure Certificate and CRL Profile","author":"Shefanovski","year":"4491"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.6028\/nist.sp.1800-16"},{"key":"ref68","volume-title":"CVE-2015-0285","year":"2015"},{"key":"ref69","volume-title":"CVE-2015-3216","year":"2015"},{"key":"ref70","volume-title":"CVE-2019-1549","year":"2019"},{"key":"ref71","doi-asserted-by":"crossref","DOI":"10.6028\/NIST.SP.800-52r2","article-title":"Guidelines for the selection, configuration, and use of transport layer security (TLS) implementations","author":"McKay","year":"2019"}],"container-title":["IEEE Transactions on Networking"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10723154\/10969151\/10758331.pdf?arnumber=10758331","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,4,18]],"date-time":"2025-04-18T04:47:51Z","timestamp":1744951671000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10758331\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,4]]},"references-count":71,"journal-issue":{"issue":"2"},"URL":"https:\/\/doi.org\/10.1109\/tnet.2024.3495617","relation":{},"ISSN":["2998-4157"],"issn-type":[{"value":"2998-4157","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,4]]}}}