Back to Search Start Over

RSA Keys Quality in a Real-world Organizational Certificate Dataset: a Practical Outlook

Authors :
Konrad Kamiński
Wojciech Mazurczyk
Source :
International Journal of Electronics and Telecommunications, Vol vol. 69, Iss No 4, Pp 803-810 (2023)
Publication Year :
2023
Publisher :
Polish Academy of Sciences, 2023.

Abstract

This research investigates the intricacies of X.509 certificates within a comprehensive corporate infrastructure. Spanning over two decades, the examined enterprise has heavily depended on its internal certificate authority and Public Key Infrastructure (PKI) to uphold its data and systems security. With the broad application of these certificates, from personal identification on smart cards to device and workstation authentication via Trusted Platform Modules (TPM), our study seeks to address a pertinent question on how prevalent are weak RSA keys within such a vast internal certificate repository. Previous research focused primarily on key sets publicly accessible from TLS and SSH servers or PGP key repositories. On the contrary, our investigation provides insights into the private domain of an enterprise, introducing new dimensions to this problem. Among our considerations are the trustworthiness of hardware and software solutions in generating keys and the consequential implications of identified vulnerabilities on organizational risk management. The obtained results can contribute to enhancing security strategies in enterprises.

Details

Language :
English
ISSN :
20818491 and 23001933
Volume :
. 69
Issue :
4
Database :
Directory of Open Access Journals
Journal :
International Journal of Electronics and Telecommunications
Publication Type :
Academic Journal
Accession number :
edsdoj.4a8f79801194b459f78756c05227f32
Document Type :
article
Full Text :
https://doi.org/10.24425/ijet.2023.147704