DocumentCode
1902699
Title
A survey of PKI components and scalability issues
Author
Slagell, Adam ; Bonilla, Rafael ; Yurcik, William
Author_Institution
Univ. of Illinois at Urbana-Champaign
fYear
2006
fDate
10-12 April 2006
Lastpage
484
Abstract
In this paper, PKI implementations, namely PKTX, SPKT and PGR are discussed. In all of these systems, there is a need to perform both efficient enrollment and revocation. We examined some of the more common certificate revocation methods. All of these solutions differ in how they balance the amount of communication between the directory and CA with the amount of communication between the directory and the end users. Additionally, some of them make trade-offs to work better in an offline environment. Lastly, we looked closely at some of the newer real-time PKI services such as OCSP, SCVP and DVCS. These services offer everything from real-time certificate status checking to complete certificate validation and verification. SCVP even allows organizations to create central points of management for all certificate handling and PKI policy enforcement. Depending on the goals and resources of a particular project, the most scalable PKI solution will look very different. Thus, it is impossible to say that PKI does or does not scale, but one can only say that a particular PM solution does or does not scale for their environment
Keywords
public key cryptography; telecommunication security; PKI implementation; certificate revocation method; enrollment; public key infrastructure;
fLanguage
English
Publisher
ieee
Conference_Titel
Performance, Computing, and Communications Conference, 2006. IPCCC 2006. 25th IEEE International
Conference_Location
Phoenix, AZ
Print_ISBN
1-4244-0198-4
Type
conf
DOI
10.1109/.2006.1629442
Filename
1629442
Link To Document