Decentralization of the Current PKI Infrastructure without Losing Backward Compatibility

Vesselin Tzvetkov · 2007

Abstract- The Public Key Infrastructure (PKI) is an important part of almost all security implementations, from secure portals for banks and e-shops to vpn devices. Although it has advantages, there is a critical design issue due the single point of failure of the root (CA) certificate. This issue is solved by decentralization of the infrastructure. Since a lot of the PKI infrastructure is already active, implementing such a solution means rebuilding the entire system from scratch. In this paper we introduce this problem and propose an industry and user friendly solution without loosing the already built PKI infrastructure. The stress of the proposed solution is on backward compatibility to the current PKI so that the smooth migration of the clients is achieved. Here we present x509v3 extensions and define the policy algorithms. Our target is to achieve an efficient solution with minimum changes in the current standards.

Read the paper · More papers on PaperTik