6 - Key Management and Distribution-Final-ok
6 - Key Management and Distribution-Final-ok
Security
16
Publicly Available Directory
CA1 CA2
A B
29
Hierarchy Model
Root CA
CA1 CA2
CA11 CA12
A B
C D E F
30
Hierarchy Model
Root’s Cert
P-Key:
4074334256
Sign: Root
CA2’s Cert
P-Key:
4074334256
Sign: Root
CA3’s Cert
User’s Cert P-Key:
P-Key: 9886543592
67150498376
Sign: CA2
Sign: CA3
31
Mesh Model
A B G H
CA1 CA4
CA2 CA3
C D E F
32
Hybrid Model
CA111 CA112 A B G H
C D E F
33
Certificate Revocation
certificates have a period of validity
may need to revoke before expiry, eg:
1. user's private key is compromised
2. user is no longer certified by this CA
3. CA's certificate is compromised
CA’s maintain list of revoked certificates
the Certificate Revocation List (CRL)
users should check certificates with CA’s CRL
X.509 Version 3