Nothing Special   »   [go: up one dir, main page]

Skip to main content

AutoPKI: A PKI Resources Discovery System

  • Conference paper
Public Key Infrastructure (EuroPKI 2007)

Part of the book series: Lecture Notes in Computer Science ((LNSC,volume 4582))

Included in the following conference series:

Abstract

The central goal of Public Key Infrastructure (PKI) is to enable trust judgments between distributed users. Although certificates play a central role in making such judgments, a PKI’s users need more than just knowledge of certificates. Minimally, a relying party must able to locate critical parameters such the certificate repositories and certificate validation servers relevant to the trust path under consideration. Users in other scenarios may require other resources and services.

Surprisingly, locating these resources and services remains a largely unsolved problem in real-world X.509 PKI deployment. In this paper, we present the design and prototype of a new and flexible solution for automatic discovery of the services and data repositories are available from a Certificate Service Provider (CSP). This contribution will take real-world PKI one step closer to achieving its goal.

The authors would like to thank Stephen Kent, Frank Pooth, Ashad Noor, Sravan and all the PKIX WG for several discussions and comments. This work was supported in part by the NSF (under grant CNS-0448499 ), the U.S. Department of Homeland Security (under Grant Award Number 2006-CS-001-000001), and Sun. The views and conclusions contained in this document are those of the authors and should not be interpreted as necessarily representing the official policies, either expressed or implied, of any of the sponsors.

This is a preview of subscription content, log in via an institution to check access.

Access this chapter

Subscribe and save

Springer+ Basic
$34.99 /Month
  • Get 10 units per month
  • Download Article/Chapter or eBook
  • 1 Unit = 1 Article or 1 Chapter
  • Cancel anytime
Subscribe now

Buy Now

Chapter
USD 29.95
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
eBook
USD 39.99
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
Softcover Book
USD 54.99
Price excludes VAT (USA)
  • Compact, lightweight edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Purchases are for personal use only

Institutional subscriptions

Preview

Unable to display preview. Download preview PDF.

Unable to display preview. Download preview PDF.

Similar content being viewed by others

References

  1. Myers, M., Ankney, R., Malpani, A., Galperin, S., Adams, C.: Online Certificate Status Protocol - OCSP. Internet Engineering Task Force: RFC 2560 (June 1999)

    Google Scholar 

  2. Wahl, M., Howes, T., Kille, S.: Lightweight Directory Access Protocol (v3). Internet Engineering Task Force: RFC 2251 (December 1997)

    Google Scholar 

  3. Freeman, T., Housley, R., Malpani, A., Cooper, D., Polk, W.: Server-based Certificate Validation Protocol (SCVP). IETF Draft (January 2007). [Online] Available http://www.ietf.org/internet-drafts/draft-ietf-pkix-scvp-31.txt

  4. OpenSSL Homepage. [Online] Available: http://www.openssl.org/

  5. OpenCA Project Homepage. [Online] Available: http://www.openca.org/

  6. OpenCA OCSPD. [Online] Available: http://www.openca.org/ocspd/

  7. World List of Universities. [Online] Available: http://www.unesco.org/iau/

  8. Universities Worldwide. [Online] Available: http://univ.cc/

  9. Hanna, S.: Follow-up Survey on Obstacles to PKI Deployment and Usage (October 2003). [Online] Available: http://www.oasis-open.org/committees/pki/pkiobstaclesaugust2003surveyreport.pdf

  10. Housley, R., Polk, W., Ford, W., Solo, D.: Certificate and Certificate Revocation List (CRL) Profile. Internet Engineering Task Force: RFC 3280 (2002)

    Google Scholar 

  11. Mockapetris, P.: Domain Names - Implementation and Specification. Internet Engineering Task Force: RFC 1035, Request for Comments (November 1987)

    Google Scholar 

  12. Gulbrandsen, A., Vixie, P., Esibov, L.: A DNS RR for specifying the location of services (DNS SRV). Internet Engineering Task Force: RFC 2782 (February 2000)

    Google Scholar 

  13. Boeyen, S., Hallam-Baker, P.: Internet X.509 Public Key Infrastructure Repository Locator Service. IETF Experimental (September 2005). [Online] Available: http://tools.ietf.org/wg/pkix/draft-ietf-pkix-pkixrep/draft-ietf-pkix-pkixrep-04.txt

  14. Curbera, F., Duftler, M., Khalaf, R., Nagy, W., Mukhi, N., Weerawarana, S.: Unraveling the Web Services Web: An Introduction to SOAP, WSDL, and UDDI. IEEE Internet Computing 6(2), 86–93 (2002). [Online] Available: http://dx.doi.org/10.1109/4236.991449

    Article  Google Scholar 

  15. Martin, G., Marc, H., Noah, M., Jean-Jacques, M., Henrik Frystyk, N.: SOAP Version 1.2. W3C Recommendation (June 2003). [Online] Available: http://www.w3.org/TR/

  16. Christensen, E., Curbera, F., Meredith, G., Weerawarana, S.: PWeb Services Description Language (WSDL) 1.1. W3C Note (March 2001). [Online] Available: http://www.w3.org/TR/2001/NOTE-wsdl-20010315

  17. Chinnici, R., Gudgin, M., Moreau, J.-J., Weerawarana, S.: Web Services Description Language (WSDL) Version 2.0 Part 1: Core Language. W3C Working (May 2005). [Online] Available: http://www.w3.org/TR/wsdl20

  18. Clement, L., Hately, A., von Riegen, C., Rogers, T.: UDDI Version 3.0.2. [Online] Available (October 2004), http://uddi.org/pubs/uddi_v3.htm

  19. Common Object Request Broker Architecture: Core Specification (March, 2004), [Online] Available: http://www.omg.org/technology/documents/corba_spec_catalog.htm

  20. Yergeau, F., Cowan, J., Bray, T., Paoli, J., Sperberg-McQueen, C.M., Maler, E.: Extensible Markup Language (XML) 1.1. W3C Recommendation (2004, February). [Online] Available: http://www.omg.org/technology/documents/corba_spec_catalog.htm

  21. Information Technology - ASN.1 encoding rules: Specification of Basic Encoding Rules (BER), Canonical Encoding Rules (CER) and Distinguished Encoding Rules (DER)ITU-T Recommendation X.690 (1994) | ISO/Uniform Resource Locators (URL)IEC 8825-1:1995 (1994)

    Google Scholar 

  22. Information Technology - ASN.1 encoding rules: Specification of Basic Encoding Rules (BER), Canonical Encoding Rules (CER) and Distinguished Encoding Rules (DER)ITU-T Recommendation X.690 (1994) | ISO/Uniform Resource Locators (URL)IEC 8825-1:1995 (1994)

    Google Scholar 

  23. Edwards, W.: Core Jini, 2nd edn. Prentice-Hall, Englewood Cliffs (2000)

    Google Scholar 

  24. Arnold, K.: The Jini Specification, 2nd edn. Addison-Wesley, Reading (2000)

    Google Scholar 

  25. Universal Plug and Play Specifications. [Online] Available: http://www.upnp.org/resources/specifications.asp

  26. Jenronimo, M., Weast, J.: UPnP Design by Example: A Software Developer’s Guide to Universal Plug and Play (2003)

    Google Scholar 

  27. Guttman, E., Perkins, C., Veizades, J., Day, M.: Service Location Protocol, version 2. Internet Engineering Task Force: RFC 2608 (June 1999)

    Google Scholar 

  28. Guttman, E., Perkins, C., Kempf, J.: Service Templates and Schemes. Internet Engineering Task Force: RFC 2609 (June 1999)

    Google Scholar 

  29. Guttman, E.: Service Location Protocol: Automatic Discovery of IP Network Services. IEEE Internet Computing 3(4), 71–80 (1999)

    Article  Google Scholar 

  30. Java RMI Specification (2003). [Online] Available: http://java.sun.com/j2se/1.4.2/docs/guide/rmi/spec/rmiTOC.html

  31. Goland, Y., Cai, T., Leach, P., Gu, Y., Albright, S.: Simple Service Discovery Protocol. IETF Draft (October 1999). [Online] Available: http://www.ietf.org/internet-drafts/draft-cai-ssdp-v1-03.txt

  32. OpenSLP Project. [Online] Available: http://www.openspl.org

  33. International Grid Trust Federation. [Online] Available: http://www.gridpma.org

  34. Education Roaming (Eduroam) Homepage. [Online] Available: http://www.eduroam.org/

Download references

Author information

Authors and Affiliations

Authors

Editor information

Javier Lopez Pierangela Samarati Josep L. Ferrer

Rights and permissions

Reprints and permissions

Copyright information

© 2007 Springer-Verlag Berlin Heidelberg

About this paper

Cite this paper

Pala, M., Smith, S.W. (2007). AutoPKI: A PKI Resources Discovery System. In: Lopez, J., Samarati, P., Ferrer, J.L. (eds) Public Key Infrastructure. EuroPKI 2007. Lecture Notes in Computer Science, vol 4582. Springer, Berlin, Heidelberg. https://doi.org/10.1007/978-3-540-73408-6_11

Download citation

  • DOI: https://doi.org/10.1007/978-3-540-73408-6_11

  • Publisher Name: Springer, Berlin, Heidelberg

  • Print ISBN: 978-3-540-73407-9

  • Online ISBN: 978-3-540-73408-6

  • eBook Packages: Computer ScienceComputer Science (R0)

Publish with us

Policies and ethics