{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,25]],"date-time":"2026-01-25T02:11:35Z","timestamp":1769307095149,"version":"3.49.0"},"reference-count":21,"publisher":"MDPI AG","issue":"2","license":[{"start":{"date-parts":[[2020,2,14]],"date-time":"2020-02-14T00:00:00Z","timestamp":1581638400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Future Internet"],"abstract":"<jats:p>Public key infrastructures (PKIs) are the cornerstone for the security of the communication layer of online services relying on certificate-based authentication, such as e-commerce, e-government, online banking, cloud services, and many others. A PKI is an infrastructure based on a hierarchical model, but the use of PKIs in non-hierarchical contexts has exposed them to many types of attacks. Here, we discuss weaknesses exploited in past attacks and we propose a solution based on an original consensus algorithm developed for use on blockchain technology. In this implementation we retain the full functionality around X.509 certificates, i.e., for the triad (server name, server address, X.509 server certificate), and demonstrate a mechanism for obtaining fast consensus. The main properties of the solution are that a consensus may be reached even when not all members of the involved PKI participate in a transaction, and that no advanced trust agreement among PKIs is needed. The proposed solution is able to detect PKI attacks and can distinguish errors from attacks, allowing precise management of anomalies.<\/jats:p>","DOI":"10.3390\/fi12020040","type":"journal-article","created":{"date-parts":[[2020,2,18]],"date-time":"2020-02-18T10:10:25Z","timestamp":1582020625000},"page":"40","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":33,"title":["A Blockchain based PKI Validation System based on Rare Events Management"],"prefix":"10.3390","volume":"12","author":[{"given":"Maurizio","family":"Talamo","sequence":"first","affiliation":[{"name":"INUIT Foundation\u2014University of Rome Tor Vergata, 00133 Rome, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Franco","family":"Arcieri","sequence":"additional","affiliation":[{"name":"INUIT Foundation\u2014University of Rome Tor Vergata, 00133 Rome, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Andrea","family":"Dimitri","sequence":"additional","affiliation":[{"name":"INUIT Foundation\u2014University of Rome Tor Vergata, 00133 Rome, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Christian H.","family":"Schunck","sequence":"additional","affiliation":[{"name":"INUIT Foundation\u2014University of Rome Tor Vergata, 00133 Rome, Italy"},{"name":"Fraunhofer Institute for Industrial Engineering IAO, Nobelstra\u00dfe 12, 70569 Stuttgart, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2020,2,14]]},"reference":[{"key":"ref_1","first-page":"1","article-title":"Internet X.509 public key infrastructure certificate and certificate revocation list (crl) profile","volume":"5280","author":"Cooper","year":"2008","journal-title":"RFC"},{"key":"ref_2","unstructured":"Prins, J., and Cybercrime, B.U. (2011). Diginotar certificate authority breach operation black tulip. Fox-IT Interim Rep."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"65439","DOI":"10.1109\/ACCESS.2018.2876971","article-title":"Proof of Delivery of Digital Assets using Blockchain and Smart Contracts","volume":"6","author":"Hasan","year":"2018","journal-title":"IEEE Access"},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Pongnumkul, S., Siripanpornchana, C., and Thajchayapong, S. (August, January 31). Performance Analysis of Private Blockchain Platforms in Varying Workloads. Proceedings of the 2017 26th International Conference on Computer Communication and Networks (ICCCN), Vancouver, BC, Canada.","DOI":"10.1109\/ICCCN.2017.8038517"},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Garay, J.A., Kiayas, A., and Leonardos, N. (2018). Bootstrapping the Blockchain with Applications to Consensus and Fast PKI setup. Public-Key Cryptography\u2014PKC 2018, Springer.","DOI":"10.1007\/978-3-319-76581-5_16"},{"key":"ref_6","unstructured":"Constantin, L. (2019, May 10). rustware Admits Issuing Man-in-the-Middle Digital Certificate; Mozilla Debates Punishment. February 2012. Available online: https:\/\/www.computerworld.com\/article\/2501291\/trustwave-admits-issuing-man-in-the-middle-digital-certificate--mozilla-debates-punishment.html."},{"key":"ref_7","unstructured":"Langley, A. (2019, May 10). Enhancing Digital Certificate Security. January 2013. Available online: http:\/\/security.blogspot.com\/2013\/01\/enhancing-digital-certificate-security.html."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"193","DOI":"10.14419\/ijet.v7i2.6.10566","article-title":"Session Hijacking and Prevention Technique","volume":"7","author":"Baitha","year":"2018","journal-title":"Int. J. Eng. Technol."},{"key":"ref_9","unstructured":"(2019, May 10). Certificate Transparency. Available online: https:\/\/www.certificate-transparency.org\/."},{"key":"ref_10","first-page":"1018","article-title":"Ikp: Turning a pki around with blockchains","volume":"2016","author":"Matsumoto","year":"2016","journal-title":"IACR Cryptol. ePrint Arch."},{"key":"ref_11","unstructured":"Wazan, A.S., Laborde, R., Barr\u00e8re, F., Benzekri, A., and Chadwick, D.W. (2009, January 27\u201331). PKI Interoperability: Still an Issue? A Solution in the X.509 Realm. Proceedings of the IFIP World Conference on Information Security Education, Bento Gon\u00e7alves, Brazil."},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Androulaki, E., Barger, A., Bortnikov, V., Cachin, C., Christidis, K., De Caro, A., Enyeart, D., Ferris, C., Laventman, G., and Manevich, Y. (2018, January 23\u201326). Hyperledger Fabric: A Distributed Operating System for Permissioned Blockchains. Proceedings of the EuroSys \u201818, Thirteenth EuroSys Conference, Porto, Portugal.","DOI":"10.1145\/3190508.3190538"},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Riabi, I., Ayed, H.K., and Saidane, L.A. (2019, January 24\u201328). A survey on Blockchain based access control for Internet of Things. Proceedings of the 2019 15th International Wireless Communications & Mobile Computing Conference (IWCMC), Tangier, Morocco.","DOI":"10.1109\/IWCMC.2019.8766453"},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Yakubov, A., Shbair, W., Wallbom, A., and Sanda, D. (2018, January 23\u201327). A Blockchain based PKI Management Framework. Proceedings of the First IEEE\/IFIP International Workshop on Managing and Managed by Blockchain (Man2Block) Colocated with IEEE\/IFIP NOMS 2018, Tapei, Tawain.","DOI":"10.1109\/NOMS.2018.8406325"},{"key":"ref_15","unstructured":"Baldi, M., Chiaraluce, F., Frontoni, E., Gottardi, G., Sciarroni, D., and Spalazzi, L. (2017, January 17\u201320). Certificate Validation through Public Ledgers and Blockchains. Proceedings of the First Italian Conference on Cybersecurity (ITASEC17), Venice, Italy."},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Al-Bassam, M. (2017, January 2\u20136). SCPKI: A Smart Contract-based PKI and Identity System. Proceedings of the ACM Workshop on Blockchain, Cryptocurrencies and Contracts, Abu Dhabi, UAE.","DOI":"10.1145\/3055518.3055530"},{"key":"ref_17","unstructured":"Roozbehani, M., Povilionis, A., Schunck, C.H., and Talamo, M. (2017, January 9\u201314). On the Fragility of Network Security Verification in Rare-Observation Regimes. Proceedings of the IFAC 2017 World Congress, Toulouse, France."},{"key":"ref_18","unstructured":"Wagner, J. (2020, February 12). Why Performance Matters. Available online: https:\/\/developers.google.com\/web\/fundamentals\/performance\/why-performance-matters."},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Gilad, Y., Hemo, R., Micali, S., Vlachos, G., and Zeldovich, N. (2017, January 28). Algorand: Scaling Byzantine Agreements for Cryptocurrencies. Proceedings of the 26th Symposium on Operating Systems Principles, Shanghai, China.","DOI":"10.1145\/3132747.3132757"},{"key":"ref_20","unstructured":"Van Der Aalst, W., Adriansyah, A., De Medeiros, A.K.A., Arcieri, F., Baier, T., Blickle, T., Bose, J.C., Van Den Brand, P., Brandtjen, R., and Buijs, J. (September, January 30). Process Mining Manifesto. Proceedings of the Business Process Management Workshops, Clermont-Ferrand, France."},{"key":"ref_21","unstructured":"Ongaro, D., and Ousterhout, J. (2019, May 10). The Raft Consensus Algorithm. Available online: https:\/\/raft.github.io\/."}],"container-title":["Future Internet"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1999-5903\/12\/2\/40\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T08:57:51Z","timestamp":1760173071000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1999-5903\/12\/2\/40"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,2,14]]},"references-count":21,"journal-issue":{"issue":"2","published-online":{"date-parts":[[2020,2]]}},"alternative-id":["fi12020040"],"URL":"https:\/\/doi.org\/10.3390\/fi12020040","relation":{},"ISSN":["1999-5903"],"issn-type":[{"value":"1999-5903","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,2,14]]}}}