• DocumentCode
    2431019
  • Title

    Simplifying PKI usage through a client-server architecture and dynamic propagation of certificate paths and repository addresses

  • Author

    Hunter, Brian

  • Author_Institution
    Fraunhofer Inst. for Secure Telecooperation, Darmstadt, Germany
  • fYear
    2002
  • fDate
    2-6 Sept. 2002
  • Firstpage
    505
  • Lastpage
    510
  • Abstract
    PKI deployment and use has not met its expectations. One reason that PKIX has not been fully accepted is due to the complexity of the system. Any application wishing to use PKI must implement complicated logic for certificate parsing, certificate path building and policy management. Certificate path building, in particular, is further complicated by the non-standardized method of certificate discovery and retrieval. Thus, many applications do not utilize or cannot utilize public key technology. We propose a new PKI server which offers access to PKI services and only requires a simple client API and a small client library that enables even resource-limited clients to be supported. This can greatly reduce application development time and complexity and allow PKI usage to propagate into more applications. Furthermore, we introduce the concept of a PKI server-to-server protocol which allows knowledge of certificate repositories and certificate paths to be shared among different PKI Servers. This technique will simplify the task of certificate retrieval and path building for individual PKI Servers.
  • Keywords
    application program interfaces; certification; client-server systems; protocols; public key cryptography; PKI; PKI server; PKI server-to-server protocol; PKIX; application development time; certificate discovery; certificate parsing; certificate path building; certificate retrieval; client API; client-server architecture; complexity; dynamic certificate path propagation; dynamic certificate repository address propagation; logic; policy management; small client library; Access protocols; Bridges; Certification; Connectors; Content addressable storage; Libraries; Logic; Proposals; Public key; Standards organizations;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Database and Expert Systems Applications, 2002. Proceedings. 13th International Workshop on
  • ISSN
    1529-4188
  • Print_ISBN
    0-7695-1668-8
  • Type

    conf

  • DOI
    10.1109/DEXA.2002.1045948
  • Filename
    1045948