home
NEWS       BLOGS       FORUMS       NEWSLETTERS       RESEARCH       EVENTS       DIGITAL LIBRARY       CAREERS  
Network Computing Network Computing Powered by InformationWeek Business Technology Network

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers



  C O L U M N 

A Pocketful of Keys

June 26, 2000
By Robert Moskowitz

Those who are striving to create a world in which there is just a single certificate for each person are misguided. A more realistic approach provides a number of certificates for each person so that more than one certificate may be in use at any given time.

Multiple certificates must exist if for no other reason than to support the multiple identities most people have on the Internet: a Hotmail address for online purchases, an ISP address for friends and families, a professional association address for business networking and so on. Additionally, there's no reason to believe that these certificates should exist in just one trust community. Multiple trust anchors (a CA's root certificate at the head of a hierarchy or within a mesh community) or multiple trust lists (a collection of CA root certificates, defining a trusted community on a single platform) will be the norm. The challenge for certificate-storage vendors is to support this model and make it easy to use.

Three major challenges face digital-certificate usage: Managing the trust communities, managing the certificates and making a user feel as comfortable using certificates as he or she feels about using ordinary keys. None of these has been uniformly addressed. Instead, too many vendors providing certificate-enabled applications are striving for user simplicity by forcing the unrealistic single-certificate/single-trust community model, rather than grappling with the tougher issues.

Consider an environment where the Web browser and e-mail program can use only a single trust list and a company wants to use a special e-mail address and certificate for moving encrypted, confidential documents within the company. Further, it wants to prevent accidental, secure mailings to nonemployees. Because e-mail programs do not usually support advanced certificate extensions (such as name constraints, policies or Extended Key Usage), the only way to restrict secure mail is to delete all but the company's CA from the trusted-root certificate list. But doing this blocks any other secure e-mail usage and causes the Web browser to issue security warnings when used for external SSL connections.

Certificate support should be moving toward labeling of security communities (that is, some form of trust model) and associating them with the user certificates (one or many per community). For example, a business user could have a top-secret community for internal product development, a special extranet community for secure business and the general public community for public Web access. A home user could have banking, health and government communities, along with the general public community. At any time, he or she could be using one or all of his or her certificates and associated trust communities.

The prospect of simultaneous usage will impact the development of certificate storage and of trust lists or anchors (two methods for defining a trust community). Smartcard technology will afford limited flexibility in a multicertificate/multitrust environment. You either put everything on one card or get multiple readers to support many cards in use at once. "Everything on one card" runs counter to the standard credit-card advice of "multiple cards in multiple places." But multiple readers will be expensive to deploy. Meanwhile, hard-drive storage is less secure as well as lacking in portability. The most compelling option today is the USB token. USB hubs are appearing in keyboards and CRTs, making it relatively easy to use a number of USB tokens simultaneously.

Public key technology has a ways to go before it delivers a secure digital future. Although many tactical applications for it exist, we will continue to stumble on one issue or another until the PKI community develops a sound road map and moves forward on strategic solutions. Managing multiple identities and trust communities is just one more item on the list.

Robert Moskowitz is a senior technical director at ICSA. Send your comments on this column to him at rgm@htt-consult.com.








Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Aneesh Chopra is looking to other CIOs to advise him on fleshing out a more detailed agenda to best serve the president's IT agenda.

IT spending is expected to decline by 3.8 percent in 2009 according to Gartner.










2009 IT Salary Survey: Meager Raises, Solid Prospects
Though raises are notably smaller than a year ago, and job security’s shrinking, IT careers are looking safer than many others in this economic downturn. Get all the findings in InformationWeek's 2009 IT Salary Survey. Available FREE for a limited time.
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



Techweb
Informationweek Business Technology Network
InformationweekInformationweek 500Informationweek 500 ConferenceInformationweek AnalyticsInformationweek Events
Informationweek MagazineGlobal CIOIWK Government ITbMightyByte and SwitchDark Reading
Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingPlug Into The CloudDr. DobbsContentinople
space
TechWeb Events Network
InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0Mobile Business ExpoNoJitter
Black HatGTECEnergy CampCloud ConnectGov 2.0 ExpoGov 2.0 Summit
space
Light Reading Communications Network
Light ReadingLight Reading AsiaUnstrungCable Digital NewsInternet EvolutionPyramid Research
Heavy ReadingLight Reading LiveLight Reading InsiderEthrnet ExpoTelco TVTower Technology Summit
space
Financial Technology Network
Advanced TradingBank Systems and TechnologyInsurance and TechnologyWall Street and TechnologyAccelerating WallstreetBST SummitBuyside Trading SummitIT Summit
space
Microsoft Technology Network
MSDNTechNetTotal IT ProTotal Dev ProNET Total Dev Pro CommunitySQL Total Dev Pro Community
space


App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |  Advertising Contacts  |   Briefing Centers
Copyright © 2009  United Business Media LLC  |  Privacy Statement  |  Terms of Service