{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,23]],"date-time":"2025-08-23T00:08:34Z","timestamp":1755907714764,"version":"3.44.0"},"publisher-location":"New York, NY, USA","reference-count":60,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,12,4]],"date-time":"2023-12-04T00:00:00Z","timestamp":1701648000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,12,4]]},"DOI":"10.1145\/3627106.3627144","type":"proceedings-article","created":{"date-parts":[[2023,12,2]],"date-time":"2023-12-02T18:13:22Z","timestamp":1701540802000},"page":"113-123","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["Delegation of TLS Authentication to CDNs using Revocable Delegated Credentials"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0005-0190-5164","authenticated-orcid":false,"given":"Daegeun","family":"Yoon","sequence":"first","affiliation":[{"name":"ETRI, KAIST, Republic of Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4323-4080","authenticated-orcid":false,"given":"Taejoong","family":"Chung","sequence":"additional","affiliation":[{"name":"Virginia Tech, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4879-1262","authenticated-orcid":false,"given":"Yongdae","family":"Kim","sequence":"additional","affiliation":[{"name":"KAIST, Republic of Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2023,12,4]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"[n. d.]. CDN Industry: Trends Size And Market Share. https:\/\/blog.intricately.com\/cdn-industry-trends-market-share-customer-size."},{"key":"e_1_3_2_1_2_1","unstructured":"[n. d.]. Disable Universal SSL certificates. https:\/\/developers.cloudflare.com\/ssl\/edge-certificates\/universal-ssl\/disable-universal-ssl\/."},{"key":"e_1_3_2_1_3_1","unstructured":"[n. d.]. Edge. https:\/\/www.microsoft.com\/en-us\/edge?form=MA13FJ&exp=e00."},{"key":"e_1_3_2_1_4_1","unstructured":"[n. d.]. Go tls package. https:\/\/pkg.go.dev\/crypto\/tls."},{"key":"e_1_3_2_1_5_1","unstructured":"[n. d.]. Google Chrome. https:\/\/www.google.com\/chrome\/."},{"key":"e_1_3_2_1_6_1","unstructured":"[n. d.]. Mozilla Firefox. https:\/\/www.mozilla.org\/en-US\/."},{"key":"e_1_3_2_1_7_1","unstructured":"[n. d.]. Network Security Services (NSS). https:\/\/firefox-source-docs.mozilla.org\/security\/nss\/index.html."},{"key":"e_1_3_2_1_8_1","unstructured":"[n. d.]. Usage statistics and market share of Cloudflare. https:\/\/w3techs.com\/technologies\/details\/cn-cloudflare."},{"key":"e_1_3_2_1_9_1","unstructured":"2013. OCSP Stapling in Firefox. https:\/\/blog.mozilla.org\/security\/2013\/07\/29\/ocsp-stapling-in-firefox\/."},{"key":"e_1_3_2_1_10_1","unstructured":"2014. Keyless SSL: The Nitty Gritty Technical Details. https:\/\/blog.cloudflare.com\/keyless-ssl-the-nitty-gritty-technical-details\/."},{"key":"e_1_3_2_1_11_1","unstructured":"2017. Geo Key Manager: How It Works. https:\/\/blog.cloudflare.com\/geo-key-manager-how-it-works\/."},{"key":"e_1_3_2_1_12_1","unstructured":"2021. How Do Browsers Handle Revoked SSL\/TLS Certificates?https:\/\/www.ssl.com\/blogs\/how-do-browsers-handle-revoked-ssl-tls-certificates\/."},{"key":"e_1_3_2_1_13_1","unstructured":"2021. Remote code execution in cdnjs of Cloudflare. https:\/\/blog.ryotak.net\/post\/cdnjs-remote-code-execution-en\/."},{"key":"e_1_3_2_1_14_1","unstructured":"2022. Apple Root Certificate Program. https:\/\/www.apple.com\/certificateauthority\/ca_program.html."},{"key":"e_1_3_2_1_15_1","unstructured":"2022. Evaluation Dashboard: OCSP failure rate. https:\/\/telemetry.mozilla.org\/new-pipeline\/dist.htmll."},{"key":"e_1_3_2_1_16_1","unstructured":"2023. CDN Usage Distribution in the Top 100k Sites. https:\/\/trends.builtwith.com\/cdn\/traffic\/Top-100k."},{"key":"e_1_3_2_1_17_1","unstructured":"2023. Chrome Root Program Policy Version 1.4. https:\/\/www.chromium.org\/Home\/chromium-security\/root-ca-policy\/."},{"key":"e_1_3_2_1_18_1","unstructured":"2023. Mozila Common CA Database (CCADB). https:\/\/ccadb-public.secure.force.com\/mozilla\/CACertificatesInFirefoxReport."},{"key":"e_1_3_2_1_19_1","unstructured":"2023. Percentage of Web Pages Loaded by Firefox Using HTTPS. https:\/\/letsencrypt.org\/stats\/#percent-pageloads."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/SEC.2018.00015"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"crossref","unstructured":"Richard Barnes Jacob Hoffman-Andrews Daniel McCarney and James Kasten. 2019. Automatic certificate management environment (acme). Technical Report.","DOI":"10.17487\/RFC8555"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978301"},{"key":"e_1_3_2_1_23_1","unstructured":"charter-ietf-doh-01. 2019. DNS Over HTTPS)."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/3487552.3487849"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/3278532.3278543"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.1983.1056650"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813703"},{"key":"e_1_3_2_1_28_1","volume-title":"26th USENIX Security Symposium (USENIX Security 17)","author":"Felt Adrienne\u00a0Porter","year":"2017","unstructured":"Adrienne\u00a0Porter Felt, Richard Barnes, April King, Chris Palmer, Chris Bentzel, and Parisa Tabriz. 2017. Measuring { HTTPS} adoption on the web. In 26th USENIX Security Symposium (USENIX Security 17). 1323\u20131338."},{"key":"e_1_3_2_1_29_1","unstructured":"Google. [n. d.]. Google Transparency Report: HTTPS encryption on the web. https:\/\/transparencyreport.google.com\/https\/overview?hl=en."},{"key":"e_1_3_2_1_30_1","volume-title":"29th USENIX Security Symposium (USENIX Security 20)","author":"Herwig Stephen","year":"2020","unstructured":"Stephen Herwig, Christina Garman, and Dave Levin. 2020. Achieving Keyless { CDNs} with Conclaves. In 29th USENIX Security Symposium (USENIX Security 20). 735\u2013751."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/3366423.3380139"},{"key":"e_1_3_2_1_32_1","unstructured":"ICANN. 2023. M7: DNSSEC Deployment. https:\/\/ithi.research.icann.org\/graph-m7.html."},{"key":"e_1_3_2_1_33_1","unstructured":"John Graham-Cumming. 2017. Incident report on memory leak caused by Cloudflare parser bug. https:\/\/blog.cloudflare.com\/incident-report-on-memory-leak-caused-by-cloudflare-parser-bug\/."},{"key":"e_1_3_2_1_34_1","volume-title":"Spectre Attacks: Exploiting Speculative Execution. In 40th IEEE Symposium on Security and Privacy (S&P\u201919)","author":"Kocher Paul","year":"2019","unstructured":"Paul Kocher, Jann Horn, Anders Fogh, , Daniel Genkin, Daniel Gruss, Werner Haas, Mike Hamburg, Moritz Lipp, Stefan Mangard, Thomas Prescher, Michael Schwarz, and Yuval Yarom. 2019. Spectre Attacks: Exploiting Speculative Execution. In 40th IEEE Symposium on Security and Privacy (S&P\u201919)."},{"key":"e_1_3_2_1_35_1","unstructured":"Kunal Anand. 2019. Security Incident Update. https:\/\/www.imperva.com\/blog\/ceoblog\/."},{"key":"e_1_3_2_1_36_1","volume-title":"13th USENIX Symposium on Networked Systems Design and Implementation (NSDI 16)","author":"Lan Chang","year":"2016","unstructured":"Chang Lan, Justine Sherry, Raluca\u00a0Ada Popa, Sylvia Ratnasamy, and Zhi Liu. 2016. Embark: Securely outsourcing middleboxes to the cloud. In 13th USENIX Symposium on Networked Systems Design and Implementation (NSDI 16). 255\u2013273."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23386"},{"key":"e_1_3_2_1_38_1","unstructured":"Hyunwoo Lee Zach Smith Junghwan Lim Gyeongjae Choi Selin Chun Taejoong Chung and Ted\u00a0Taekyoung Kwon. 2019. maTLS: How to Make TLS middlebox-aware?. In NDSS."},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2014.12"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3559336"},{"key":"e_1_3_2_1_41_1","volume-title":"27th USENIX Security Symposium (USENIX Security 18)","author":"Lipp Moritz","year":"2018","unstructured":"Moritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher, Werner Haas, Anders Fogh, Jann Horn, Stefan Mangard, Paul Kocher, Daniel Genkin, Yuval Yarom, and Mike Hamburg. 2018. Meltdown: Reading Kernel Memory from User Space. In 27th USENIX Security Symposium (USENIX Security 18)."},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1145\/2815675.2815685"},{"key":"e_1_3_2_1_43_1","unstructured":"Matthew Prince Daniel Stinson-Diess Sourov Zaman. 2022. The mechanics of a sophisticated phishing scam and how we stopped it. https:\/\/blog.cloudflare.com\/2022-07-sms-phishing-attacks\/."},{"key":"e_1_3_2_1_44_1","unstructured":"Mozilla.[n. d.]. Network Monitor. https:\/\/firefox-source-docs.mozilla.org\/devtools-user\/network_monitor\/."},{"key":"e_1_3_2_1_45_1","unstructured":"Mozilla.[n. d.]. Network request details. https:\/\/firefox-source-docs.mozilla.org\/devtools-user\/network_monitor\/request_details\/index.html#Timings."},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/3143361.3143383"},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1145\/2829988.2787482"},{"key":"e_1_3_2_1_48_1","volume-title":"15th USENIX Symposium on Networked Systems Design and Implementation (NSDI 18)","author":"Poddar Rishabh","year":"2018","unstructured":"Rishabh Poddar, Chang Lan, Raluca\u00a0Ada Popa, and Sylvia Ratnasamy. 2018. { SafeBricks} : Shielding Network Functions in the Cloud. In 15th USENIX Symposium on Networked Systems Design and Implementation (NSDI 18). 201\u2013216."},{"key":"e_1_3_2_1_49_1","unstructured":"RFC 2308. 1998. Negative Caching of DNS Queries (DNS NCACHE)."},{"key":"e_1_3_2_1_50_1","unstructured":"RFC 2535. 1999. Domain Name System Security Extensions."},{"key":"e_1_3_2_1_51_1","unstructured":"RFC 3845. 2004. DNS Security (DNSSEC) NextSECure (NSEC) RDATA Format."},{"key":"e_1_3_2_1_52_1","unstructured":"RFC 5280. 2008. Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile."},{"key":"e_1_3_2_1_53_1","unstructured":"RFC 6698. 2012. The DNS-Based Authentication of Named Entities (DANE) Transport Layer Security (TLS) Protocol: TLSA."},{"key":"e_1_3_2_1_54_1","unstructured":"RFC 6960. 2013. X.509 Internet Public Key Infrastructure Online Certificate Status Protocol - OCSP."},{"key":"e_1_3_2_1_55_1","unstructured":"RFC 8198. 2017. Aggressive Use of DNSSEC-Validated Cache."},{"key":"e_1_3_2_1_56_1","unstructured":"RFC 8446. 2018. The Transport Layer Security (TLS) Protocol Version 1.3."},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"crossref","unstructured":"Richard Barnes Subodh Iyengar Nick Sullivan and Eric Rescorla. 2022. Delegated Credentials for (D)TLS draft-ietf-tls-subcerts-15.","DOI":"10.17487\/RFC9345"},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1145\/2785956.2787502"},{"key":"e_1_3_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00089"},{"key":"e_1_3_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1145\/3127479.3127482"}],"event":{"name":"ACSAC '23: Annual Computer Security Applications Conference","acronym":"ACSAC '23","location":"Austin TX USA"},"container-title":["Annual Computer Security Applications Conference"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3627106.3627144","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3627106.3627144","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T17:40:26Z","timestamp":1755884426000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3627106.3627144"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,12,4]]},"references-count":60,"alternative-id":["10.1145\/3627106.3627144","10.1145\/3627106"],"URL":"https:\/\/doi.org\/10.1145\/3627106.3627144","relation":{},"subject":[],"published":{"date-parts":[[2023,12,4]]},"assertion":[{"value":"2023-12-04","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}