Light-weight PKI-Enabling through the Service of a Central Signature Server
Malek Bechlaghem · 2004
The main complexities, for an organization considering PKI-enabling, are related to the constraints inherent to performing the validation of digital signatures and certificates. So PKI-aware applications must support the complex logic to perform certificate path construction and validation, and retrieval of certificates. Such operations require lots of communications with directories and databases, each of them using different protocols that the PKI-aware application should implement to access them. In this paper, we consider an organization willing to PKI-enable its applications. We study the issues related to PKI-enabling in the point of view of the organization presenting the reasons why we think that PKI adoption and rollout has not become a reality yet. Then we propose a model where we are able to resolve most of the issues related to PKI-enabling. Our model relies on server-generated signatures that relieve the application from most of the tasks related to signature validation. These keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves.