Development of Certificate Authority services for web applications
Sufyan T. F. Al-Janabi, Amer Kais Obaid · 2012
The most important security services are confidentiality, integrity, authentication, and non-repudiation. When designing a communication system, the security services of this system must be defined. The Public-Key Infrastructure (PKI) is a technology that can meet these security services with its techniques and standards. A PKI system works by having a Certificate Authority (CA) for issuing public-key certificates. The aim of this work is to design and implement a CA system that can create and assign public key certificates. Hence, the system enables secure communication and proper authentication. Besides the basic security requirements, the developed system uses an approach that can contribute in facilitating the revocation of the certificates. It also gives these certificates additional security/performance advantage by using the Elliptic Curve Cryptography (ECC) instead of the RSA cryptography. The design and implementation of the proposed system have been achieved using PHP and HTML programming languages besides MySQL database server and Apache web server.