90 likes | 459 Views
XML Key Management Specification XKMS. Dr Phillip Hallam-Baker FBCS CEng. VeriSign Inc. The Trust Model Problem. PKI is the interface between the Internet and the Real World Real World Trust Relationships are complex Scale breaks simplifying assumptions used to make PKI tractable
E N D
XML Key Management Specification XKMS Dr Phillip Hallam-Baker FBCS CEng.VeriSign Inc.
The Trust Model Problem • PKI is the interface between the Internet and the Real World • Real World Trust Relationships are complex • Scale breaks simplifying assumptions used to make PKI tractable • Simple PKI Hierarchy (PEM) • Everyone is a trust provider (PGP)
AgencyCA 1 Bridge AgencyCA 2 Alice Bob FBCA PKI Topology • Federal Government Bridge CA • Not a simple hierarchy • Not a completely random assembly • Knowledge of structure greatly helps use • How to get to ubiquitous COTS support
Directory ASN1 PKIX Traditional PKI Directory Alice Bob ASN1 PKIX
Directory Directory XKMS ASN1 PKIX XML XKMS PKI Interface Alice Bob ASN1 PKIX
Directory Directory XKMS XKMS ASN1 ASN1 PKIX PKIX XML XML XKMS PKI Interface Alice Bob
XKMS Services • Key Information Service • I need a key to talk S/MIME to alice@somewhere.test • Locate – Not a Trusted Service • Validate – Trusted Service • Key Registration Service • Key lifecycle management • Registration • Reissue • Revocation • Recovery
Summary • XKMS is one example of a Web Service • Moving complexity from client to server reduces • Deployment costs • Deployment cycle time • Development costs • Management costs