Authors:
            
                    Zhi Guan
                    
                        
                                1
                            
                    
                    ; 
                
                    Abba Garba
                    
                        
                                2
                            
                    
                    ; 
                
                    Anran Li
                    
                        
                                1
                            
                    
                    ; 
                
                    Zhong Chen
                    
                        
                                1
                            
                    
                     and
                
                    Nesrine Kaaniche
                    
                        
                                2
                            
                    
                    
                
        
        
            Affiliations:
            
                    
                        
                                1
                            
                    
                    Institute of Software, EECS, Peking University, National Engineering Research Center for Software Engineering, Peking University, Beijing, China, SAMOVAR, Telecom SudParis, CNRS, University of Paris-Saclay and France
                
                    ; 
                
                    
                        
                                2
                            
                    
                    MoE Key Lab of High Confidence Software Technologies, Peking University, Beijing, China, SAMOVAR, Telecom SudParis, CNRS, University of Paris-Saclay and France
                
        
        
        
        
        
             Keyword(s):
            PKI, Blockchain, Authentication, Cryptography.
        
        
            
                
                
            
        
        
            
                Abstract: 
                Nowadays public key infrastructure authentication mainly rely on certificate authorities and have to be trusted by both domain operators and domain owners. Domain Name System Security Extensions (DNSSEC) using DNS-based Authentication Name Entities (DANE) DNS records types, offer additional security for authenticating data and integrity to domain name system (DNS). This method allow client via signed statements to specify which CAs are authorized to represent certificate of a domain. Another method is Certificate Authority Authorizations (CAA) developed by Internet Engineering Task Force (IETF) to provide security guarantee against rogue certificate authorities that offer fake certificate for the domain. However, all of these approaches are prone to single point of failure due to their trust attached to infrastructure like Internet Corporation for Assigned Names and Numbers (ICANN). In order to weaken the level of trust to the CAs over certificates, it is necessary to balance the dis
                tribution rights among the entities and improve the control of certificate issuance for the certificate owners. Recently with the emergence of Blockchain, a public and distributed ledger, several applications appeared taking advantage of this powerful technology. In this paper, we present an AuthLedger a domain authentication scheme based on blockchain technology. The proposed scheme is multi-fold. First, we proposed a domain authentication scheme to reduce the level of trust in CAs. second, we implement our system using Ethereum smart contract. Third, we evaluate security and performance of the proposed system.
                (More)