Skip to main content
QUICK REVIEW

[论文解读] No domain left behind: is Let's Encrypt democratizing encryption?

Maarten Aertsen, Maciej Korczyński|arXiv (Cornell University)|Dec 9, 2016
Internet Traffic Analysis and Secure E-voting参考文献 17被引用 5
一句话总结

本文通过分析 Let's Encrypt (LE) 的首年证书颁发情况,调查其是否成功实现了网络加密的民主化。利用证书透明度日志,研究显示 LE 已迅速扩展——在一年内颁发了 1200 万张证书,其中 98% 面向 Alexa 排名前 100 万名以外的域名,主要服务于低成本共享主机,且在 25,000 个域名的样本中实现了 63% 的实际部署率,表明其对网络中未充分覆盖群体产生了广泛影响。

ABSTRACT

The 2013 National Security Agency revelations of pervasive monitoring have lead to an "encryption rush" across the computer and Internet industry. To push back against massive surveillance and protect users privacy, vendors, hosting and cloud providers have widely deployed encryption on their hardware, communication links, and applications. As a consequence, the most of web traffic nowadays is encrypted. However, there is still a significant part of Internet traffic that is not encrypted. It has been argued that both costs and complexity associated with obtaining and deploying X.509 certificates are major barriers for widespread encryption, since these certificates are required to established encrypted connections. To address these issues, the Electronic Frontier Foundation, Mozilla Foundation, and the University of Michigan have set up Let's Encrypt (LE), a certificate authority that provides both free X.509 certificates and software that automates the deployment of these certificates. In this paper, we investigate if LE has been successful in democratizing encryption: we analyze certificate issuance in the first year of LE and show from various perspectives that LE adoption has an upward trend and it is in fact being successful in covering the lower-cost end of the hosting market.

研究动机与目标

  • 评估 Let's Encrypt 是否通过降低 X.509 证书颁发的成本和复杂性,成功实现了网络加密的民主化。
  • 分析 Let's Encrypt 在运营首年所颁发证书的受众特征与主机市场分布。
  • 通过扫描代表性域名样本,评估 Let's Encrypt 证书在现实世界中的部署效果。
  • 识别推动 Let's Encrypt 采用的主要主机提供商,并评估其在扩大加密网络流量中的作用。
  • 衡量 Let's Encrypt 所颁发证书的持久性与续订行为,以评估其持续采用情况。

提出的方法

  • 从证书透明度(CT)日志中收集 Let's Encrypt 运营首年内的证书颁发数据。
  • 根据域名是否存在于 Alexa 排名前 100 万名列表中,对域名进行分类,以评估其市场覆盖范围。
  • 通过分析域名所有权和主机基础设施,将证书颁发映射到主机提供商。
  • 对包含 Let's Encrypt 证书的 25,000 个域名样本执行主动 HTTPS 扫描,以衡量其现实世界中的部署情况。
  • 使用 DNS 和 TLS 探测,确定证书是否在 443 端口正确配置并可访问。
  • 通过排除无响应、配置错误或已过期的域名,计算正确部署的保守下限估计值。

实验结果

研究问题

  • RQ1Let's Encrypt 在多大程度上将加密扩展到了网络中高流量、高价值之外的低流量、低关注度的域名?
  • RQ2哪些主机提供商是 Let's Encrypt 证书快速采用的主要推动者?
  • RQ3Let's Encrypt 证书在网页服务器上的实际成功部署率是多少?
  • RQ4Let's Encrypt 证书的续订行为与预期相比如何,能否反映其持续使用情况?
  • RQ5新域名和长期存在的域名在多大程度上从 Let's Encrypt 的免费证书中受益?

主要发现

  • Let's Encrypt 在其首年共颁发了 1200 万张证书,使其成为全球三大证书颁发机构之一。
  • 98% 的 Let's Encrypt 颁发证书面向 Alexa 排名前 100 万名以外的域名,表明其在低成本、低知名度网络主机市场中具有强大渗透力。
  • 47% 的所有 Let's Encrypt 证书域名由三家提供商托管——Automattic/wordpress.com、Shopify 和 OVH,凸显了主要主机平台在推动采用方面的作用。
  • 70% 的 Let's Encrypt 证书域名在首个 90 天证书到期后仍保持活跃,表明其具有较强的续订意愿和持续使用能力。
  • 在 25,000 个域名的样本中,63% 的证书被正确部署并通过 HTTPS 可访问,代表了实际部署的保守下限估计值。
  • Let's Encrypt 为 .nl 顶级域中的新旧域名均颁发了证书,表明即使长期存在的域名也能从主机提供商的大规模颁发中受益。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。