From pretty good to great: Enhancing PGP using bitcoin and the blockchain

Duane Wilson, Giuseppe Ateniese

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

70 Scopus citations

Abstract

PGP is built upon a Distributed Web of Trust in which a user’s trustworthiness is established by others who can vouch through a digital signature for that user’s identity. Preventing its wholesale adoption are a number of inherent weaknesses to include (but not limited to) the following: 1) Trust Relationships are built on a subjective honor system, 2) Only first degree relationships can be fully trusted, 3) Levels of trust are difficult to quantify with actual values, and 4) Issues with the Web of Trust itself (Certification and Endorsement). Although the security that PGP provides is proven to be reliable, it has largely failed to garner large scale adoption. In this paper, we propose several novel contributions to address the aforementioned issues with PGP and associated Web of Trust. To address the subjectivity of the Web of Trust, we provide a new certificate format based on Bitcoin which allows a user to verify a PGP certificate using Bitcoin identity-verification transactions - forming first degree trust relationships that are tied to actual values (i.e., number of Bitcoins transferred during transaction). Secondly, we present the design of a novel Distributed PGP key server that leverages the Bitcoin transaction blockchain to store and retrieve our certificates.

Original languageEnglish
Title of host publicationNetwork and System Security - 9th International Conference, NSS 2015, Proceedings
EditorsShouhuai Xu, Meikang Qiu, Haibo Zhang, Moti Yung
Pages368-375
Number of pages8
DOIs
StatePublished - 2015
Event9th International Conference on Network and System Security, NSS 2015 - New York, United States
Duration: 3 Nov 20155 Nov 2015

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume9408
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference9th International Conference on Network and System Security, NSS 2015
Country/TerritoryUnited States
CityNew York
Period3/11/155/11/15

Fingerprint

Dive into the research topics of 'From pretty good to great: Enhancing PGP using bitcoin and the blockchain'. Together they form a unique fingerprint.

Cite this