A distributed key generation technique for public key infrastructures

  • Authors:
  • Chenxi Wang;William A. Wulf

  • Affiliations:
  • Department of Computer Science, University of Virginia, Charlottesville, VA 22903, USA E-mail: cw2e@virginia.edu;National Academy of Engineering E-mail: wwulf@nae.edu

  • Venue:
  • Netnomics
  • Year:
  • 2000

Quantified Score

Hi-index 0.00

Visualization

Abstract

Public Key Infrastructures (PKI) are important for the security of many networked systems. The current designs of PKIs often rely on a centralized key Certification Authority (CA) for the certification and distribution of keys. This centralized entity poses a performance and scalability bottleneck. In addition, it creates a serious security risk – if the CA is penetrated, the security of the entire system is irretrievably compromised. In this paper, we present an innovative method to generate globally unique keys in a completely distributed fashion. The ability to perform distributed key generation facilitates decentralized PKIs. We present security analysis of the method as well as a set of experimental performance results. Our method scales well, and is cryptographically strong.