TY - GEN
T1 - A PKI approach targeting the provision of a minimum security level within Internet
AU - Laurent-Maknavicius, Maryline
PY - 2007/8/2
Y1 - 2007/8/2
N2 - After decades of expansion, Internet became an essential tool useful for professionals and private individuals providing a large range of services like emailing, management of bank accounts, reservation of hotels, train time schedules, real time traffic information, Internet search... If not targeted at the beginning, Information System Security became rapidly a key challenge for professionals and strong security solutions emerged on the market mainly for professionals. Internet security is thus today two-speed: pretty strong security for professionals or private individuals anxious to protect their computer equipments and no security for professionals or private individuals who can not afford security products and do no have sufficient technical expertise to set up cheap solutions by themselves. In this context, this paper targets the provision of a minimum security level within Internet by defining a PKI solution based on LDAP and DNS (extended with DNSSEC). The originality of the paper is related to the design of the chain of trust that is built over both LDAP and DNSSEC PKIs, the certificate verification method, and indications to extend those concepts to the secure emailing application.
AB - After decades of expansion, Internet became an essential tool useful for professionals and private individuals providing a large range of services like emailing, management of bank accounts, reservation of hotels, train time schedules, real time traffic information, Internet search... If not targeted at the beginning, Information System Security became rapidly a key challenge for professionals and strong security solutions emerged on the market mainly for professionals. Internet security is thus today two-speed: pretty strong security for professionals or private individuals anxious to protect their computer equipments and no security for professionals or private individuals who can not afford security products and do no have sufficient technical expertise to set up cheap solutions by themselves. In this context, this paper targets the provision of a minimum security level within Internet by defining a PKI solution based on LDAP and DNS (extended with DNSSEC). The originality of the paper is related to the design of the chain of trust that is built over both LDAP and DNSSEC PKIs, the certificate verification method, and indications to extend those concepts to the secure emailing application.
U2 - 10.1109/ECUMN.2007.3
DO - 10.1109/ECUMN.2007.3
M3 - Conference contribution
AN - SCOPUS:34547346888
SN - 076952768X
SN - 9780769527680
T3 - Proceedings - ECUMN 2007: Fourth European Conference on Universal Multiservice Networks
SP - 433
EP - 438
BT - Proceedings - ECUMN 2007
T2 - ECUMN 2007: Fourth European Conference on Universal Multiservice Networks
Y2 - 14 February 2007 through 16 February 2007
ER -