• DocumentCode
    1400077
  • Title

    Requiring Strong Credentials: What´s Taking So Long?

  • Author

    Miller, H. Gilbert ; Fisher, James L.

  • Volume
    12
  • Issue
    1
  • fYear
    2010
  • Firstpage
    57
  • Lastpage
    60
  • Abstract
    Individuals can already purchase digital certificates through the General Services Administration´s (GSA´s) Access Certificates for Electronic Services (ACES) program or through VeriSign, Thawte, and the like. Federal employees, contractors, and Web servers could have their digital certificates issued through the Federal PKI Common Policy program. In other words, the complete solution is in place if only someone would use it. This reluctance is particularly puzzling, given that these stronger authentication and authorization infrastructures are foundational for the secure data access and transactions that must conform to federal privacy laws and industry´s best practices. Without strong credentials, support for the next generation of secure automation simply can´t occur. And even more important, smartcard credentials that include digital certificates are already mandatory for federal employees and contractors.
  • Keywords
    authorisation; certification; public key cryptography; authentication infrastructures; authorization infrastructures; certificate revocation lists; digital certificates; federal privacy laws; public-key infrastructure; secure data access; smartcard credentials; Authentication; Authorization; Automation; Best practices; Data privacy; Web server; Smart IT; authentication; authorization; cybersecurity; digital certificates; public-key infrastructure (PKI);
  • fLanguage
    English
  • Journal_Title
    IT Professional
  • Publisher
    ieee
  • ISSN
    1520-9202
  • Type

    jour

  • DOI
    10.1109/MITP.2010.34
  • Filename
    5403180