• DocumentCode
    1902699
  • Title

    A survey of PKI components and scalability issues

  • Author

    Slagell, Adam ; Bonilla, Rafael ; Yurcik, William

  • Author_Institution
    Univ. of Illinois at Urbana-Champaign
  • fYear
    2006
  • fDate
    10-12 April 2006
  • Lastpage
    484
  • Abstract
    In this paper, PKI implementations, namely PKTX, SPKT and PGR are discussed. In all of these systems, there is a need to perform both efficient enrollment and revocation. We examined some of the more common certificate revocation methods. All of these solutions differ in how they balance the amount of communication between the directory and CA with the amount of communication between the directory and the end users. Additionally, some of them make trade-offs to work better in an offline environment. Lastly, we looked closely at some of the newer real-time PKI services such as OCSP, SCVP and DVCS. These services offer everything from real-time certificate status checking to complete certificate validation and verification. SCVP even allows organizations to create central points of management for all certificate handling and PKI policy enforcement. Depending on the goals and resources of a particular project, the most scalable PKI solution will look very different. Thus, it is impossible to say that PKI does or does not scale, but one can only say that a particular PM solution does or does not scale for their environment
  • Keywords
    public key cryptography; telecommunication security; PKI implementation; certificate revocation method; enrollment; public key infrastructure;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Performance, Computing, and Communications Conference, 2006. IPCCC 2006. 25th IEEE International
  • Conference_Location
    Phoenix, AZ
  • Print_ISBN
    1-4244-0198-4
  • Type

    conf

  • DOI
    10.1109/.2006.1629442
  • Filename
    1629442