PKI design for the real world

  • Authors:
  • Peter Gutmann

  • Affiliations:
  • University of Auckland New Zealand

  • Venue:
  • NSPW '06 Proceedings of the 2006 workshop on New security paradigms
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

What would a PKI look like if it were designed for implementability and deployability rather than strict adherence to a particular theoretical or mathematical model? This paper presents and examines the results of a series of interviews in which a cross-section of experienced programmers, system administrators, and technical project managers with many years of practical, real-world experience were asked which technologies they would use to solve some of the major problems that occur in PKI implementation. The results of the interviews and various significant issues identified by them are presented and discussed. Finally, a PKI technology blueprint based on recommendations made by respondents is presented. The resulting design is noteworthy in that it is almost completely unlike the one proposed in X.509 and related standards, which would indicate that at least some of the deployment difficulties being encountered with X.509-style PKIs are due to their suboptimal choice of technology.