Protection Profiles for Certificate Issuing & Management Systems
نویسنده
چکیده
At the heart of many recent efforts to improve Internet security are a group of security protocols such as S/MIME, TLS, and IPSec. All of these protocols rely on public-key cryptography to help provide services such as confidentiality, data integrity, data origin authentication, and non-repudiation. Support for this public-key cryptography is provided by a Public Key Infrastructure, or PKI. The PKI is responsible for binding public keys into certificates and managing those certificates throughout their life-cycle. The part of the PKI directly responsible for generation, issuance, and revocation of certificates is referred to as the Certificate Issuing and Management System, or CIMS. It is important to many potential CIMS customers to understand the level of security provided by a specific product or service. Furthermore, in order to accurately compare products and services from many different sources, built using many different architectures, there should be one set of requirements that can be used to evaluate CIMS. This set of requirements should be written in internationally accepted terms, such as the Common Criteria. Furthermore, it should be generic enough so that it can be used for a wide variety of architectures, but sound enough so that it can be used to provide a meaningful evaluation. This paper describes the development of a set of Common Criteria Protection Profiles that can be used to evaluate CIMS products and services.
منابع مشابه
Managing Interoperability in Non-Hierarchical Public Key Infrastructures
This paper discusses considerations for certificate issuing systems and certificate processing applications, and directory systems in environments that employ nonhierarchical public key infrastructures (PKIs). The observations and recommendations here, while applicable to almost any non-hierarchical PKI, are most relevant to situations where the establishment of interoperability among the PKIs ...
متن کاملDelegation Issuing Service for X . 509
This paper describes the concept of a delegation issuing service (DIS), which is a service that issues X.509 attribute certificates on behalf of an attribute authority (typically a manager). The paper defines the X.509 certificate extensions that are being proposed for the 2005 edition of X.509 in order to implement the DIS concept, as well as the additional steps that a relying party will need...
متن کاملChains of Distrust: Towards Understanding Certificates Used for Signing Malicious Applications
Digital certificates are key component of trust used by many operating systems. Modern operating systems implement a form of digital signature verification for various applications, including kernel driver installation, software execution, etc. Digital signatures rely on digital certificates that authenticate the signature, which then verify the validity of a given signature for a signed binary...
متن کاملEnabling the Provisioning and Management of a Federated Grid Trust Fabric
In order to authenticate and authorize users and other peer-services, Grid services need to maintain a list of authorities that they trust as a source for issuing credentials. Grids inherently span multiple institutional administration domains and aim to support the sharing of applications, data, and computational resources in a collaborative environment. In this environment there may exist hun...
متن کاملCertificate Issuing Using Proxy and Threshold Signatures in Self-initialized Ad Hoc Network
In ad hoc network, it is very crucial to issue certificates safely in the self-initialized scheme where the system authority exists only at the beginning of the network operation. In order to solve this problem, early studies have presented some suggestions by removing the system authority itself and using certificate chain, or by making nodes act as system authorities for issuing other nodes’ ...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 1999