PKI trust relationships: from a hybrid architecture to a hierarchical model
Cristina Satizábal, Rafael Páez, Jordi Forné
Abstract
Cristina Satizábal, Rafael Páez, Jordi Forné
Abstract
Trust models provide a framework to create and manage trust relationships among the different entities of a public key infrastructure (PKI). These trust relationships are verified through the certification path validation process, which involves: path discovery, signature verification and revocation status checking. When trust relationships are bidirectional, multiple paths can exist between two entities, which increase the runtime of the path discovery process. In addition, validation of long paths can be difficult, especially when storage and processing capacities of the verifier are limited. In this paper, we propose a protocol to establish a hierarchical trust model from a PKI with unidirectional and bidirectional trust relationships. This protocol makes more efficient the path validation process since in a hierarchical model, trust relationships are unidirectional and paths are easy to find. In addition, our protocol allows setting a maximum path length, so it can be adapted to the features of users' terminals.
OpenAlex reports 12 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Trust models provide a framework to create and manage trust relationships among the different entities of a public key infrastructure (PKI). These trust relationships are verified through the certification path validation process, which involves: path discovery, signature verification and revocation status checking. When trust relationships are bidirectional, multiple paths can exist between two entities, which increase the runtime of the path discovery process. In addition, validation of long paths can be difficult, especially when storage and processing capacities of the verifier are limited. In this paper, we propose a protocol to establish a hierarchical trust model from a PKI with unidirectional and bidirectional trust relationships. This protocol makes more efficient the path validation process since in a hierarchical model, trust relationships are unidirectional and paths are easy to find. In addition, our protocol allows setting a maximum path length, so it can be adapted to the features of users' terminals.
Key concepts: Public key infrastructure, Computer science, Trust anchor, Revocation, Path (computing), Process (computing), Protocol (science), Public-key cryptography