An overview of PKI trust models
An overview of PKI trust models
复制标题
DOI:
10.1109/65.806987
复制
发表时间:
1999-11-01
期刊:
影响因子:
9.3
通讯作者:
Perlman, R
中科院分区:
文献类型:
--
作者:
Perlman, R
If Alice and Bob each know their own private key and the other's public key, they can communicate securely, through any number of public-key based protocols such as IPSec [1], PGP [2], S/MIME [3], or SSL [4]. However, how do they know each other's public keys? The goal of a public key infrastructure (PKI) is to enable public keys. It should be applicable secure, convenient, and efficiency discovery of public keys It should be applicable as well as between organizations, and scalable to support the Internet There are various types of PKI that are widely deployed or have been proposed. They differ in the configuration information required, trust rules, and flexibility There ore standards such as X.509 [5] and PKIX [6], but these are sufficiently flexible so that almost any model of PKI con be supported. In this article we describe several types of PKI and discuss the advantages and disadvantages of each. We argue against several popular and widely deployed models as being insecure, unscalable, or overly inconvenient. We also recommend a particular model.