Reykjavík University
Lookey : building a public key database to discover the origin of compromised private keys
Abstract
dc:description.abstractThe lack of security online has been a growing concern in recent years with companies and individuals having a lot to lose in the case of a security breach. With increasing cyber security concerns, many services have opted for more secure methods of authentication than simple usernames and passwords. One such approach is using asymmetric cryptographic keys. Individuals tend to be more concerned with their passwords getting leaked than their private keys. This is of great concern since these keys have appeared in data leaks, and have been used for malicious purposes, e.g. to gain unauthorized access to sensitive data. However, given a private key found in a leak without relevant metadata, discovering the context of it is no trivial task. In this paper we aim to answer the research question: What are the challenges in creating a system capable of identifying the owner and uses of a cryptographic private key, given only the key itself? We evaluate methods of gathering and storing vast amounts of public keys along with their relevant metadata, while offering a fast lookup to match a leaked private key to a stored public key. To perform the lookup, we created Lookey: a system that uses the derived public key of a given private key to get information about the key’s use or context. By using Lookey, one can possibly find and notify the owner of a leaked private key.
Author and committee
dc:creator, dc:contributor.*- Authors dc:creator
-
- Guðjón Ingi Valdimarsson 2000-
- Halla Margrét Jónsdóttir 1999-
- Ísól Sigurðardóttir 1997-
- Contributors dc:contributor
-
- Háskólinn í Reykjavík
Subjects
dc:subject × 10Rights
- Language dc:language.iso
- en
Identifiers
dc:identifier.*- Handle dc:identifier.uri
- http://hdl.handle.net/1946/42014
- OAI identifier oai:identifier
- oai:skemman.is:1946/42014