The key to trust? signalling quality in the PKI market
نویسندگان
چکیده
The absence of a platform for secure electronic commerce is widely recognised. Across the globe, a host of Certification Authorities (CAs) have emerged to seize the opportunity for issuing digital certificates that constitute the Public Key Infrastructure (PKI). Yet the take-up of the technology has been bitterly disappointing. The market for digital certificates has failed to reach the critical worldwide mass that was anticipated. Current literature suggests a variety of outstanding technical, legal and policy issues that hinder the adoption of PKI. We argue that another contributing factor in this adverse turn of events is the quality uncertainty surrounding CAs and the certificates they issue. This paper adopts the Lemons principle, an economic theory, to analyse the market situation of quality uncertainty and reviews three countermeasures that remedy this problem: brand names, guarantees and licensing. Applying this economic theory to the PKI market, the paper discusses how these three countermeasures might be used to signal the quality of certificates and hence generate the trust missing between CAs and relying parties in electronic transactions.
منابع مشابه
Spotting Lemons in the PKI Market: Engendering Trust by Signalling Quality
Public key infrastructure (PKI) has emerged as a critical technology for identity management in e-commerce and e-government and over a hundred Certification Authorities across the globe offer certification services. Despite the passing of legislation in many countries to give equal legal weight to electronic signatures as to handwritten ones, the overall market for digital certificates has not ...
متن کاملInter/Intra Core Network Security with PKI for 3G-and-Beyond Systems
With a large number of different heterogeneous network technologies (e.g. UMTS, WLAN, HIPERLAN) and operators expected in the future mobile communications environment, that should frequently and seamlessly interwork with each other and a constantly increasing population of communication parties, capturing the full benefits of open channel key transfers and scaling public key methods requires Pu...
متن کاملRisk and Trust Management Techniques RISK AND TRUST MANAGEMENT TECHNIQUES FOR AN “OPEN BUT BOUNDED” PUBLIC KEY INFRASTRUCTURE
Establishing trustworthiness requires an analysis of the business, technical and legal requirements for each party to a Public Key Infrastructure (PKI) based transaction. Much of the current discussion about PKI requirements revolves around the license, accreditation, or other sets of ratings as applied to certification authorities (CA). It is becoming apparent that an exclusive focus on CA qua...
متن کاملPKI Interoperability by an Independent, Trusted Validation Authority
Interoperability between PKIs (Public Key Infrastructure) is a major issue in several electronic commerce scenarios. This paper suggests an approach based on a trust model where an independent Validation Authority (VA) replaces Certification Authorities (CA) as the trust anchor for the receiver of a PKI certificate (the Relying Party, RP). By trusting the VA, the RP is able to trust all CAs tha...
متن کاملTrust and Public Key Infrastructure
In the current rocket-speed growing E-commerce market, certain infrastructure, which enables users to exchange information and money securely over the Internet, is essential. Unfortunately, Internet is mere a cloud of connections of nodes. There is no organization to operate and manage. So the Internet itself is not responsible for any malicious frauds and attacks, and failures caused by reliab...
متن کامل