Where to get a closer look at PKI

Opinion
Sep 3, 20033 mins

* Resources for public-key infrastructure definitions

Some people can criticize in such a nice way. After last month’s newsletter about Voltage Technology and its Identity-Based Encryption software (see links below) one very nice reader wrote to say, “Perhaps your readers will benefit from a clarification of the PKI concepts you left hanging …” It was better than saying “Hey bozo, you really mucked up the whole PKI concept, didn’t you?”

In my defense, I never claimed to be a security expert but then I’m always quick to take to task those who attempt to comment outside their area of expertise. So what I’ll do in this case is to defer to my newsletter colleague M. E. Kabay, who writes Network World’s security newsletter (and who preaches what he practices as Associate Professor in the Department of Computer Information Systems at Norwich University).

His recommendation comes from the newsletter “A treatise on Internet security,” published last year (see links below). In it, he recommends that folks get a free copy of a 212-page report called “Safe and Sound: A Treatise on Internet Security” written by Stephen Sigmond, managing director, and Vikram Kaura, senior associate of RBC Capital markets.

While the report itself is now almost two years old, the concepts are still valid and need to be understood. The report can be downloaded after registering (at https://www.rbcdrw.com/security) – nothing onerous, just the usual name, address, phone and e-mail. You can even get a nifty poster sent to you which illustrates the concepts in the report (you can view the poster at https://infosecuritymag.techtarget.com/2002/apr/pdfs/mosaic.pdf but it’s a large PDF file and slow to load).

In the report, according to Kabay, “…the authors break down authentication solutions into public-key infrastructure software and services and non-PKI solutions. They then look at authorization software, intrusion-detection software and appliances, vulnerability assessment, Internet access control, content security and managed security services.”

Certainly they’ll do a better job of explaining PKI to you than I would. Still, if you want to know even more you might look for the 1999 book “Understanding Public-Key Infrastructure,” published by MacMillan. The authors (Carlisle Adams and Steve Lloyd) have many, many years of security experience and take an exhaustive look at the PKI technology in this 300-page tome.  The authors were both at Entrust Technologies when they wrote the book (and Adams, at least, is still there, as far as I know) so they have an excellent understanding of identity management (even though the phrase itself wasn’t well known at the time they wrote).

It’s not exciting reading, but it’s probably essential reading to understand security as it’s practiced today.