PKI Design Based on the Use of On-line Certification Authorities

TitlePKI Design Based on the Use of On-line Certification Authorities
Publication TypeJournal Article
Year of Publication2004
AuthorsJ. Lopez, A. Mana, J. A. Montenegro, and J. J. Ortega
JournalInternational Journal of Information Security (IJIS)
ISSN Number1615-5262

Public-Key Infrastructures (PKIs) are considered the basis of the protocols and tools needed to guarantee the security demanded for new Internet applications like electronic commerce, government-citizen relationships and digital distribution. This paper introduces a new infrastructure design, Cert’eM, a key management and certification system that is based on the structure of the electronic mail service and on the principle of near-certification. Cert’eM provides secure means to identify users and distribute their public-key certificates, enhances the efficiency of revocation procedures, and avoids scalability and synchronization problems. Because we have considered the revocation problem as priority in the design process, and with a big influence in the rest of the PKI components, we have developed an alternative solution to the use of Certificate Revocation Lists (CRLs), which has become one of the strongest points in this new scheme.

Citation KeyJavierLopez2004b
Paper File: