PKI applications (C2)

Basics and legal aspects

Pascal Steichen (MSSI-uni.lu) - 17/03/2007 (02)

Where it all started

The problem with symmetric key crypto-systems:


© 1999 Department of Computer Science and Information Systems, The University of Hong Kong

1. PKI basics

Recap of the fundamentals and basic concepts:

1.1. Data encryption using PKI


© 1999 Department of Computer Science and Information Systems, The University of Hong Kong

1.1.1. Example: SSL/TLS

1.2. Digital signature using PKI (1)


© 1999 Department of Computer Science and Information Systems, The University of Hong Kong

Digital signature using PKI (2)


© 2006 Bart Van den Bosch

1.3. Key management in PKI (1)


© 1999 Department of Computer Science and Information Systems, The University of Hong Kong


© 1999 Department of Computer Science and Information Systems, The University of Hong Kong

Key management in PKI (2)


© 1999 Department of Computer Science and Information Systems, The University of Hong Kong


© 1999 Department of Computer Science and Information Systems, The University of Hong Kong

1.4. CA and certificates


© 1999 Department of Computer Science and Information Systems, The University of Hong Kong

1.4.1. Example certificate (1)

Example certificate

Example certificate (2)

2. Ten risks of PKI


© 2000 Computer Security Journal • Volume XVI, Number 1, Bruce Schneier

3. Trust models

or PKI vs PGP

Web of trust

3.1. PKI trust models/architectures

4. Legal aspects

4.1. Electronic signature directive (1999/93/EC) (1)

Electronic signature directive (1999/93/EC) (2)

Electronic signature directive (1999/93/EC) (3)

Electronic signature directive (1999/93/EC) (4)

Electronic signature directive (1999/93/EC) (5)

Electronic signature directive (1999/93/EC) (6)

Electronic signature directive (1999/93/EC) (7)

4.2. LU legal framework (1)

LU legal framework (2)

LU legal framework (3)

LU legal framework (4)

4.3. CSP supervision/accreditation legal framework (1)

CSP supervision/accreditation legal framework (2)

CSP supervision/accreditation legal framework (3)

CSP supervision/accreditation legal framework (4)

CSP supervision/accreditation legal framework (5)

4.4. CSP accreditation scheme

4.5. CSP supervision scheme