Merkle Tree Certificates reimagine transparency for the Web PKI by integrating transparency logs into certificate issuance. This applies many of this community’s transparency innovations to certificate issuance, from tiled logs to witness cosignatures. In putting this together, MTC introduced some new constructions of its own. In this talk, we’ll discuss these and how they might apply to other transparency applications. This talk will discuss subtrees (how to efficiently talk about portions of a log), pruning (a tile-compatible way to remove old entries, while maintaining meaningful guarantees on the rest), and mirrors (generalized witnesses that serve a copy of the log).
Speaker
David Benjamin is a software engineer and tech lead on Chrome’s Networking Security team and BoringSSL. While perpetually distractible, his work primarily focuses on cryptography, TLS, PKI, and Internet standards. He is one of the authors of the Merkle Tree Certificates specification. When he’s not busy running around in the Internet, you will find him turning clay or molten sand into somewhat rotationally-symmetric objects.