Paper 2026/642

SoK: The Weakest-Link Principle in Public Key Infrastructures and Modern Mitigation Strategies

Kertis Mwanza, Bochum University of Applied Sciences
Carsten Köhn, Bochum University of Applied Sciences
Abstract

As digital transformation accelerates, securing communication through hierarchical Public Key Infrastructures (PKIs) is increasingly critical. Yet, this centralized trust architecture remains inherently vulnerable. As a Systematization of Knowledge (SoK), this paper maps the threat landscape of hierarchical PKIs, demonstrating how a compromise at any single node from a Root CA breach to an operational revocation failure can trigger a cascading loss of global trust. Grounded in the Weakest-Link Principle, our analysis reveals that a PKI ecosystem is only as resilient as its least protected vector. Traditional revocation mechanisms, particularly CRLs and OCSP, exhibit significant operational and privacy flaws, and are often rendered ineffective by client-side "soft-fail" policies. To address these vulnerabilities, we advocate for a shift: replacing unconditional trust in individual entities with decentralized,verifiable protocols. We evaluate Certificate Transparency (CT) as a core mitigation strategy, illustrating how append-only Merkle trees make misissuance publicly visible and cryptographically auditable. Finally, we synthesize essential operational hardening measures such as strict key cryptoperiods and procedural policies to ensure long-term ecosystem resilience.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Preprint.
Keywords
PKICertificate TransparencyVulnerability AnalysisWeakest-Link PrincipleOCSP-Stapling
Contact author(s)
kertis mwanza @ stud hs-bochum de
carsten koehn @ hs-bochum de
History
2026-04-04: approved
2026-04-01: received
See all versions
Short URL
https://ia.cr/2026/642
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/642,
      author = {Kertis Mwanza and Carsten Köhn},
      title = {{SoK}: The Weakest-Link Principle in Public Key Infrastructures and Modern Mitigation Strategies},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/642},
      year = {2026},
      url = {https://eprint.iacr.org/2026/642}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.