【24h】

Usable trust anchor management

机译:可用的信任锚管理

获取原文

摘要

Security in browsers is based upon users trusting a set of root Certificate Authorities (called Trust Anchors) which they may know little or nothing about. Browser vendors face a difficult challenge to provide an appropriate interface for users. Providing usable Trust Anchor Management (TAM) for users, applications and PKI deployers is a complex task. The PKIX working group at Internet Engineering Task Force (IETF) is working on a new protocol, the Trust Anchor Management Protocol (TAMP), which will provide a standardized method to automatically manage trust anchors in applications and devices. Although promising, this protocol does not go far enough to allow users to gather information about previously unknown trust anchors in an automatic fashion. We have proposed the PKI Resource Query Protocol (PRQP)---which is currently an Internet Draft on Experimental Track with IETF---to provide applications with an automatic discovery system for PKI management. In this paper we describe the basic architecture and capabilities of PRQP that allow Browsers to provide a more complete set of trust anchor management services. We also provide the design of a PRQP enabled infrastructure that uses a trust association mechanism to provide an easy solution for managing Trust Anchors for Virtual Organizations.
机译:浏览器的安全性基于用户信任一组可能很少了解或一无所知的根证书颁发机构(称为信任锚)。浏览器供应商面临着为用户提供适当界面的艰巨挑战。为用户,应用程序和PKI部署程序提供可用的信任锚管理(TAM)是一项复杂的任务。 Internet工程任务组(IETF)的PKIX工作组正在研究一种新协议,即信任锚管理协议(TAMP),它将提供一种标准化方法来自动管理应用程序和设备中的信任锚。尽管该协议很有前途,但它还远远不足以允许用户以自动方式收集有关先前未知的信任锚的信息。我们已经提出了PKI资源查询协议(PRQP),它是当前使用IETF进行实验的Internet草案,旨在为应用程序提供用于PKI管理的自动发现系统。在本文中,我们描述了PRQP的基本体系结构和功能,这些功能允许浏览器提供更完整的信任锚管理服务集。我们还提供了支持PRQP的基础结构的设计,该基础结构使用了信任关联机制来为管理虚拟组织的信任锚提供简单的解决方案。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号