Protection Profiles for Certificate Issuing & Management Systems

نویسنده

  • A. Arsenault
چکیده

At the heart of many recent efforts to improve Internet security are a group of security protocols such as S/MIME, TLS, and IPSec. All of these protocols rely on public-key cryptography to help provide services such as confidentiality, data integrity, data origin authentication, and non-repudiation. Support for this public-key cryptography is provided by a Public Key Infrastructure, or PKI. The PKI is responsible for binding public keys into certificates and managing those certificates throughout their life-cycle. The part of the PKI directly responsible for generation, issuance, and revocation of certificates is referred to as the Certificate Issuing and Management System, or CIMS. It is important to many potential CIMS customers to understand the level of security provided by a specific product or service. Furthermore, in order to accurately compare products and services from many different sources, built using many different architectures, there should be one set of requirements that can be used to evaluate CIMS. This set of requirements should be written in internationally accepted terms, such as the Common Criteria. Furthermore, it should be generic enough so that it can be used for a wide variety of architectures, but sound enough so that it can be used to provide a meaningful evaluation. This paper describes the development of a set of Common Criteria Protection Profiles that can be used to evaluate CIMS products and services.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Managing Interoperability in Non-Hierarchical Public Key Infrastructures

This paper discusses considerations for certificate issuing systems and certificate processing applications, and directory systems in environments that employ nonhierarchical public key infrastructures (PKIs). The observations and recommendations here, while applicable to almost any non-hierarchical PKI, are most relevant to situations where the establishment of interoperability among the PKIs ...

متن کامل

Delegation Issuing Service for X . 509

This paper describes the concept of a delegation issuing service (DIS), which is a service that issues X.509 attribute certificates on behalf of an attribute authority (typically a manager). The paper defines the X.509 certificate extensions that are being proposed for the 2005 edition of X.509 in order to implement the DIS concept, as well as the additional steps that a relying party will need...

متن کامل

Chains of Distrust: Towards Understanding Certificates Used for Signing Malicious Applications

Digital certificates are key component of trust used by many operating systems. Modern operating systems implement a form of digital signature verification for various applications, including kernel driver installation, software execution, etc. Digital signatures rely on digital certificates that authenticate the signature, which then verify the validity of a given signature for a signed binary...

متن کامل

Enabling the Provisioning and Management of a Federated Grid Trust Fabric

In order to authenticate and authorize users and other peer-services, Grid services need to maintain a list of authorities that they trust as a source for issuing credentials. Grids inherently span multiple institutional administration domains and aim to support the sharing of applications, data, and computational resources in a collaborative environment. In this environment there may exist hun...

متن کامل

Certificate Issuing Using Proxy and Threshold Signatures in Self-initialized Ad Hoc Network

In ad hoc network, it is very crucial to issue certificates safely in the self-initialized scheme where the system authority exists only at the beginning of the network operation. In order to solve this problem, early studies have presented some suggestions by removing the system authority itself and using certificate chain, or by making nodes act as system authorities for issuing other nodes’ ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 1999