An overview of PKI trust models

An overview of PKI trust models
复制标题

DOI:
10.1109/65.806987
复制
发表时间:
1999-11-01
期刊:
影响因子:
9.3
通讯作者:
Perlman, R
Perlman, R
中科院分区:
计算机科学2区
文献类型:
--
作者:
Perlman, R

文献摘要

被引文献

相似文献

如果爱丽丝和鲍勃都知道自己的私钥和对方的公钥,他们可以通过任意数量的基于公钥的协议进行安全通信,例如IPSec[1]、PGP[2]、S/MIME[3]或SSL[4]。然而,他们是如何知道对方的公钥的?公钥基础设施(PKI)的目标是启用公钥。它应该是适用的、安全的、方便的和高效的公钥发现它应该适用于组织之间和组织之间,并且可以扩展以支持互联网。各种类型的PKI被广泛部署或已经被提出。它们在所需的配置信息、信任规则和灵活性方面与X.509[5]和PKIX[6]等标准有所不同,但这些标准足够灵活,几乎可以支持任何PKI模型。在本文中,我们描述了几种类型的PKI,并讨论了每种类型的优缺点。我们反对几个流行的和广泛部署的模型,认为它们不安全、不可伸缩或过于不方便。我们还推荐一种特殊的型号。
If Alice and Bob each know their own private key and the other's public key, they can communicate securely, through any number of public-key based protocols such as IPSec [1], PGP [2], S/MIME [3], or SSL [4]. However, how do they know each other's public keys? The goal of a public key infrastructure (PKI) is to enable public keys. It should be applicable secure, convenient, and efficiency discovery of public keys It should be applicable as well as between organizations, and scalable to support the Internet There are various types of PKI that are widely deployed or have been proposed. They differ in the configuration information required, trust rules, and flexibility There ore standards such as X.509 [5] and PKIX [6], but these are sufficiently flexible so that almost any model of PKI con be supported. In this article we describe several types of PKI and discuss the advantages and disadvantages of each. We argue against several popular and widely deployed models as being insecure, unscalable, or overly inconvenient. We also recommend a particular model.