• DocumentCode
    2822638
  • Title

    Scalable policy driven and general purpose public key infrastructure (PKI)

  • Author

    Prasad, Vishwa ; Potakamuri, Sreenivasa ; Ahern, Michael ; Lerner, Michah ; Balabine, Igor ; Dutta, Partha

  • Author_Institution
    AT&T Labs., Lincroft, NJ, USA
  • fYear
    2000
  • fDate
    36861
  • Firstpage
    138
  • Lastpage
    147
  • Abstract
    This paper describes a flexible and general purpose PKI platform. Providing an easily interoperable security infrastructure. Developed at AT&T Labs, the architecture is part of the UCAID/Internet2 efforts in PKI and scalable security. The architecture can host multiple certificate authorities (CAs) from different vendors in a uniform and scalable manner. This facilitates scalable operation with third-party CA systems. It acts as a CA distributor driven by uniform enrollment procedures based on vendor independent PKI policies. The design of seamless integration facilitates easy integration with third party CA services such as Verisign. The architecture adapts software components into a framework for secure, authenticated IP services over the open Internet or within internal intranets. Policy descriptions, written in XML, support explicit controls upon certificate sources and contents. These XML-encoded policies define issuance and acceptance of X.509v3 certificates from multiple CAs supporting the obligations and warrantees, even if the policy is neither recorded anywhere nor referenced in the certificate. The PKI component has been developed within a general middleware platform
  • Keywords
    certification; client-server systems; message authentication; public key cryptography; software architecture; AT&T Labs; CRL; CRML; OCSP; PKCS; Verisign; X.509v3 certificates; X509; XML; authenticated IP services; authentication; certificate sources; interoperable security infrastructure; intranets; middleware platform; multiple certificate authorities; policy descriptions; public key infrastructure; revocation; third-party CA systems; uniform enrollment procedures; Authentication; Computer architecture; Content addressable storage; Digital signatures; Internet; Mobile communication; Protocols; Public key; Security; XML;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Security Applications, 2000. ACSAC '00. 16th Annual Conference
  • Conference_Location
    New Orleans, LA
  • Print_ISBN
    0-7695-0859-6
  • Type

    conf

  • DOI
    10.1109/ACSAC.2000.898867
  • Filename
    898867