Title :
Autonomous Decentralized Root Certification Authority System
Author :
Coronado-García, Luis Carlos ; Hernández-López, Carlos ; Pérez-Leguízamo, Carlos
Author_Institution :
Technol. Res. Group, Banco de Mexico, Mexico City, Mexico
Abstract :
A public key infrastructure (PKI) is a set of elements and procedures needed to create, store, manage, distribute and revoke digital certificates. Its main objective is to bind public keys with respective user identities assuring the uniqueness of these public keys. A PKI must guarantee the reliability of its services, assuring the timeliness of its responses and the continuity of the service despite of the growth in the number of users and the presence of hardware or software failures. Avoiding duplication of public keys due to intentional or involuntary errors is mandatory in a PKI, hence the verification of public keys uniqueness is a fundamental task. In this paper we propose a model in which a PKI is constituted by the following entities: a root certification authority (root-CA) responsible for issuing Authorities´ certificates and verifying the uniqueness of the public keys issued on its own or by any of the others authorities belonging to this PKI, a number of certification authorities (CA´s) which issue end user´s certificates, and a number registration authorities (RA´s), which store the user certificates. In our PKI model the root certification authority has a main role and it is clear that could become a bottle neck in a real implementation; in order to avoid this risk, we have tried to benefit from autonomous decentralized systems concepts and have proposed an approach in which the root certification authority has the properties of an ADS, namely on-line expandability, on-line maintenance and fault tolerance. Two are the main contributions of this paper, first we apply ADS concepts in a PKI model and, second show a software implementation of an ADS architecture.
Keywords :
authorisation; certification; public key cryptography; software reliability; PKI; autonomous authority system; certification authorities; decentralized root certification authority system; digital certificates; fault tolerance; hardware failures; on-line expandability; on-line maintenance; public key infrastructure; registration authorities; root-CA; service continuity; software failures; Application software; Broadcasting; Certification; Computer architecture; Content management; Cyclic redundancy check; Fault tolerant systems; Hardware; Process control; Public key; Autonomous Decentralized System; Fault-Tolerance; High Reliability; Public Key Cryptography; Public Key Infrastructure;
Conference_Titel :
Distributed Computing Systems Workshops, 2009. ICDCS Workshops '09. 29th IEEE International Conference on
Conference_Location :
Montreal, QC
Print_ISBN :
978-0-7695-3660-6
Electronic_ISBN :
1545-0678
DOI :
10.1109/ICDCSW.2009.58