Inhouse PKIs
A PKI can also be implemented by an enterprise for internal use to authenticate employees accessing the network. In this case, the enterprise is its own certificate authority (CA). For details on the public key system, see cryptography.
Managing the Root Key
The root key is the public/private key pair of the certificate authority. If the private part of that root key is ever discovered, all the certificates issued under that key pair are compromised. Creating and keeping the private key very private is critical.
All Encompassing
The PKI establishes the encryption algorithms, levels of security and distribution policy to users. The PKI embraces all the software (browsers, e-mail programs, etc.) used to support the process by examining and validating the certificates and signed messages. See digital certificate, digital signature, root key, web of trust and DST.
Generating the Root Key
SafeNet's Luna CA3 is a hardware security module (HSM) that is used to generate the root key in a PKI system and keep the private key secure. It uses a pin entry device (PED), EEPROM-based data keys and a PC Card reader that attaches to the server via an LVDS cable and PCI adapter. Containing a processor, firewall, flash memory and RAM, the PC Card is built with extra epoxy and secured with triple DES encryption. The card will destroy its contents if compromised.
The PED combines and transfers information from the data keys to the PC Card. The blue key is inserted into the PED by the security officer who sets up administrative rights, configures the HSM and determines how many people must use green keys. All parties must insert their green keys to activate the system. The black keys are used by administrators to generate and delete key pairs, and the red keys are used for grouping HSMs in domains. (Image courtesy of SafeNet, Inc., www.safenet-inc.com)
![]() | Reproduced with permission from Computer Desktop Encyclopedia. Copyright (c) 1981-2009 The Computer Language Company Inc. All rights reserved. |
Additional Resources
- SimpleAuthority 2.6 (Windows)
- SimpleAuthority is a Certification Authority CA that is designed to be very easy to use. It generates and manages keys and certificates for people and/or computer servers that can be used for secure email, VPN access, client/server SSL authentication and other uses. Unlike most CA products, SimpleAuthority is very easy...
- Software downloads 2009-11-18
- Secure Medical Email Hosting 2.9.6 (Mac)
- Medical Doctor's HIPAA compliant email, manage PHI and voice transcription. Collaborate with Instant Messaging, File Sharing and Private Message Boards. Send and Receive secure email, share documents and patient information. HIPAA and GLBA compliant. Works across networks and firewalls without a need for expensive VPN, PKI or complicated network setup...
- Software downloads 2009-10-16
- Secure Medical Email Hosting 2.9.6 (Windows)
- Medical Doctor's HIPAA compliant email, manage PHI and voice transcription. Collaborate with Instant Messaging, File Sharing and Private Message Boards. HIPAA and GLBA compliant. Works across networks and firewalls without a need for expensive VPN, PKI or complicated network setup and maintenance. Formally comply with privacy and security provisions of:...
- Software downloads 2009-10-14
- CryptoHeaven 2.9.6 (Mac)
- Send and receive secure and anonymous email. Backup, store and share files online securely. Chat and exchange secure instant messages, create secure message boards. Share document folders through easy to use interface. Communication and collaborate with your co-workers and friends accross networks and firewalls with very high level of security...
- Software downloads 2009-10-13
- Ending DNS abuse with European open source
- Ending DNS abuse with European open sourceDNS has been flawed much longer than that...Over the past 10 years, there have been numerous attacks on the DNS system. Successful cache poisonings have caused, and continue to cause millions of dollars in damage and tens of thousands of virus infected PCs.As of...
- Discussion threads 2009-07-31
- Data Security Mythbusters: Public Key Infrastructure (PKI)
- In today's business environment, enterprises must work even harder than before to protect one of their most valuable assets - their information. When facing the pressures of regulatory oversight, email security, business-to-business requirements, and increased threats to networked environments, organizations must be proactive in protecting their data. A single loss...
- White papers 2009-07-27
- Why Outsourcing Your PKI Provides the Best Value: A Total Cost of Ownership Analysis
- Once one conclude that one needs a certificate to exchange information online securely, turn on the security inherent in existing applications, or authenticate to users, computers, VPN, the Web, or buildings, the next point of determination is: how can I do this cost-effectively without forfeiting quality? The answer is simple:...
- White papers 2009-07-02
- Sub-Prime PKI: Attacking Extended Validation SSL
- One of the attributes that the paper discusses is the type of SSL certificate presented by a web server when negotiating a secure connection. Modern web browsers support both Domain Validated DV and Extended Validation EV SSL certificates. EV SSL certificates were created to combat phishing and other web based...
- White papers 2009-07-01
- PKI and UDDI Based Trust Centre: An Attempt to Improve Web Service Security
- Nowadays Internet becomes the most used tool for the ever increasing amount of various transactions between institutions, organizations and more generally between clients and providers. Conducted studies and experiments showed that it is more convenient to provide and achieve these transactions as Web Services WS to guarantee their flexibility and...
- White papers 2009-06-29
- CoSign Digital Signatures for SaaS Applications: Increasing Value and Collaboration
- In many SaaS applications there is a need to regularly complete various documentation, forms, and transactions that also require approvals in the form of an electronic signature. In addition, the electronic records created must be verified and trusted by any recipient around the world - this means parties inside a...
- White papers 2009-06-23
- VeriSign PKI-Based Certificates Are Rock Solid: From the Tumultuous Launch of the Integrated Cargo System to Today
- Representing 250 customs brokers and freight forwarding businesses in Australia, the Customs Brokers and Forwarders Council of Australia Inc. CBFCA is an industry association that represents members' interests in various Australian Customs and Border Protection Service consultative forums - providing members with guidance, representation, services and access to the latest...
- Case studies 2009-06-17
- The PKI Authentication System With the Integration of Biometric Identification and Nonsymmetric Key Technology
- To deal with the threats to the PKI authentication system from the internet and the real world, based on the analysis of biometric identification and nonsymmetric key technology, this paper presented a new PKI authentication system through the integration of Biometric identification and non-symmetric key technology, which assembled their advantages...
- White papers 2009-05-24
- Earth System Grid Authentication Infrastructure: Integrating Local Authentication, OpenID and PKI
- Climate scientists face a wide variety of practical problems, but there exists an overarching need to efficiently access and manipulate climate model data. Increasingly, for example, researchers must assemble and analyze large datasets that are archived in different formats on disparate platforms, and must extract portions of datasets to compute...
- White papers 2009-05-20
- Deduplication will exist everywhere
- Deduplication will exist everywhereGlobal DedupePlease make sure to factor in Global Dedupe as well in your report. Without it, you dont have a scalable nor in some cases a redundant system.Datacastle PC Backup & Data ProtectionDatacastle offers five best of breed components in one enterprise PC data privacy solution...
- Discussion threads 2009-04-27
- Comodo Certificate Manager for PKI Administration: Centrally Managing Enterprise Security, Trust & Regulatory Compliance
- Digital certificates PKI protect information assets by supporting data encryption, authentication and integrity while at rest or in-transport. Certificates enable user identity and access validation, SSL encryption, and are employed to digitally sign and authenticate web content, process documents, email messages and software programs. Orchestrating this broad landscape of preventive,...
- White papers 2009-04-27
- Secure Email and PKI Certificate Management Made Easy by Comodo
- Business-sensitive information is often distributed by unsecured email, and in doing so it's placed at risk. The same ease and utility that allows internal users, partners and customers to effectively communicate can be allowing confidential information to be in easy reach of those who want to profit from it. To...
- White papers 2009-04-27
- National PKI: The Foundation of Trust in Government Programs
- Governments around the world are gearing up to deliver the next generation of services to their citizens. They want to accept digitally signed tax returns. Execute electronic transactions securely. Tighten border control. They want to do all this while maintaining strong security, streamlining administration, and containing operational costs. The challenge...
- White papers 2009-03-20
- Email Encryption for InterScan Messaging Hosted Security: An Overview of the Email Encryption Add-On Service for Trend Micro's Hosted Email Security
- Trend Micro offers Email Encryption as an add-on service to InterScan Messaging Hosted Security. It integrates seamlessly with the content filtering capabilities of Trend Micro's hosted email security service that protects against spam, viruses and inappropriate content. Trend Micro Email Encryption leverages Identity-Based Encryption IBE to efficiently secure email addressed...
- White papers 2009-03-12
- Email Encryption for InterScan Messaging Hosted Security
- With policy-based encryption, organizations avoid relying on individual users to secure important content. Conveniently, encryption is automatically applied when content filtering rules are triggered, helping to ensure that confidentiality and privacy requirements are met. Trend Micro provides a policy-based email encryption solution that seamlessly integrates with the content filtering capabilities...
- White papers 2009-02-20
- VeriSign Enables a Major Satellite Internet Service Provider to Further Promote Security and Affordability
- WildBlue Communications, Inc. is an Internet service provider that delivers reliable broadband connection via satellite for people in remote and rural areas requiring high-speed Internet connectivity. The challenge was to enhance security and integrity by leveraging open standards-based X.509 PKI digital certificates for device authentication, the need to keep the...
- Case studies 2009-02-18
Neighboring Terms
Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
- The best support in the Linux business
-
If Linux is going to power your mission-critical applications, you'd better have the best support known to business. Novell was rated the top provider of Linux technical support.
- Learn more >>
- Keep Up With The Latest In Document Management with The DocuMentor.
-
> Doc delivers the scoop on today's enterprise content management, printer maintenance, and all other issues related to document management. It's the DocuMentor Blog.
- Learn more >>
- The best support in the Linux business
-
If Linux is going to power your mission-critical applications, you'd better have the best support known to business. Novell was rated the top provider of Linux technical support.
- Learn more >>
- New Online Dashboard for IT Leaders
-
Read about top issues IT decision-makers face every day, plus get cost-effective solutions to real-life IT problems.
- Learn more >>
Meet Doc
-
Here to help you with your Document Management Needs
- Doc is an enigma. Born to a Russian ballerina and a German electrical engineer, he grew up in various locations in the United States. He’s seen the insides of more brands, versions, and generations of printer and printer-related hardware than almost anyone.
- To learn more about this mysterious figure check out his blog on ZDNet and his Workspace on TechRepublic. You’ll be glad you did.
-
Produced by
ZDNet and








