PKI implementation issues in B2B e-commerce

Pita Jarupunphol, Chris J. Mitchell, Chris J. Mitchell · Royal Holloway Digital Repository (Royal Holloway University of London) · 2003

The security of sensitive information transmitted and stored during ecommerce transactions is clearly an overriding issue of concern to organisations and individuals. Not only is there a need for the protection of the confidentiality and integrity of sensitive information, but verification of the identity of a communicating party is often also necessary. Public Key Infrastructures or PKIs have long been promoted as an important part of a solution to these concerns, since they support the wide scale use of public key cryptography to fulfil end-user security requirements. Although PKIs involving a single CA are effective when implemented within a well-defined population, the implementation of PKIs across multiple domains and hence involving multiple CAs, e.g. as required for e-commerce, has encountered serious problems. The intention of this paper is to discuss the main reasons for the PKI implementation issues in B2B e-commerce and to propose potential solutions.

Read the paper · More papers on PaperTik