Design and implementation of PKI-based certification authority
Ying Zheng, Bai Qing-hai, Lin-Na Zhao, Chun Hua, Jing Chen · Proceedings of SPIE, the International Society for Optical Engineering/Proceedings of SPIE · 2015
PKI achieves the management of public key by certificates. It combines the user’s public key and his or her identification formation through a trusted third-party organization CA, in order to authenticate the user’s identity on the Internet, thus ensuring the authenticity, integrity, confidentiality, and non- repudiation of the information transmitted on the Internet. CA is the most critical agency in the PKI system, mainly responsible for issuing and managing certificates. On the basis of the actual needs of an enterprise, in this paper the author designs and develops a small-sized PKI-based Certification Authority equipped with the functions of root CA initialization, certificate application, certificate issuance, certificate revocation, and the generation of certificate revocation list. The author also points out the problems that need to be mentioned in the design and development.