Assessing SSL/TLS Certificate Centralization: Implications for Digital Sovereignty

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Azevedo, Andrei Cordova, Scheid, Eder John, Franco, Muriel Figueredo, Granville, Lisandro Zambenedetti
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909593431441408
author Azevedo, Andrei Cordova
Scheid, Eder John
Franco, Muriel Figueredo
Granville, Lisandro Zambenedetti
author_facet Azevedo, Andrei Cordova
Scheid, Eder John
Franco, Muriel Figueredo
Granville, Lisandro Zambenedetti
contents SSL/TLS is a fundamental technology in the network protocol stack that enables encrypted data transmission and authentication of web domains. However, the current model relies on a small number of Certificate Authorities (CAs) to provide and validate certificates, thus creating a highly centralized ecosystem. In this paper, we analyze the degree of centralization of certificate provisioning from CAs in two major political groups: Brazil, Russia, India, China, and South Africa (BRICS) and the European Union (EU). We have found that over 75% of certificates for both BRICS and EU domains originate from CAs based in the United States, indicating possible risks to their digital sovereignty due to the high level of external dependency. This indicates the need for nations within those groups to research alternatives to reduce the high level of dependency on foreign CAs and increase their digital autonomy.
format Preprint
id arxiv_https___arxiv_org_abs_2504_16897
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Assessing SSL/TLS Certificate Centralization: Implications for Digital Sovereignty
Azevedo, Andrei Cordova
Scheid, Eder John
Franco, Muriel Figueredo
Granville, Lisandro Zambenedetti
Networking and Internet Architecture
SSL/TLS is a fundamental technology in the network protocol stack that enables encrypted data transmission and authentication of web domains. However, the current model relies on a small number of Certificate Authorities (CAs) to provide and validate certificates, thus creating a highly centralized ecosystem. In this paper, we analyze the degree of centralization of certificate provisioning from CAs in two major political groups: Brazil, Russia, India, China, and South Africa (BRICS) and the European Union (EU). We have found that over 75% of certificates for both BRICS and EU domains originate from CAs based in the United States, indicating possible risks to their digital sovereignty due to the high level of external dependency. This indicates the need for nations within those groups to research alternatives to reduce the high level of dependency on foreign CAs and increase their digital autonomy.
title Assessing SSL/TLS Certificate Centralization: Implications for Digital Sovereignty
topic Networking and Internet Architecture
url https://arxiv.org/abs/2504.16897