PKI applications (C2)

Basics and legal aspects

Pascal Steichen (MSSI-uni.lu) - 07/12/2007

Where it all started

The problem with symmetric key crypto-systems:


© 1999 Department of Computer Science and Information Systems, The University of Hong Kong

1. PKI basics

Recap of the fundamentals and basic concepts:

1.1. Data encryption using PKI


© 1999 Department of Computer Science and Information Systems, The University of Hong Kong

1.1.1. Example: SSL/TLS

1.2. Digital signature using PKI


© 1999 Department of Computer Science and Information Systems, The University of Hong Kong

Digital signature using PKI (2)


© 2006 Bart Van den Bosch

1.3. Key management in PKI


© 1999 Department of Computer Science and Information Systems, The University of Hong Kong

Key management in PKI (2)


© 1999 Department of Computer Science and Information Systems, The University of Hong Kong

Key management in PKI (3)


© 1999 Department of Computer Science and Information Systems, The University of Hong Kong

Key management in PKI (4)


© 1999 Department of Computer Science and Information Systems, The University of Hong Kong

1.4. CA and certificates


© 1999 Department of Computer Science and Information Systems, The University of Hong Kong

1.4.1. Example certificate

Example certificate

Example certificate (2)

2. Trust models (or PKI vs PGP)

Web of trust (an example)


© 2007 The Philadelphia area Linux User Group (PLUG)

2.1. PKI trust models (architectures)

PKI trust models (architectures) (2)

3. Ten risks of PKI


© 2000 Computer Security Journal • Volume XVI, Number 1, Bruce Schneier

4. Legal aspects

4.1. Electronic signature directive (1999/93/EC)

Electronic signature directive (1999/93/EC) (2)

Electronic signature directive (1999/93/EC) (3)

Electronic signature directive (1999/93/EC) (4)

Electronic signature directive (1999/93/EC) (5)

Electronic signature directive (1999/93/EC) (6)

Electronic signature directive (1999/93/EC) (7)

4.2. LU legal framework

LU legal framework (2)

LU legal framework (3)

LU legal framework (4)

4.3. CSP supervision/accreditation legal framework

CSP supervision/accreditation legal framework (2)

CSP supervision/accreditation legal framework (3)

CSP supervision/accreditation legal framework (4)

CSP supervision/accreditation legal framework (5)

4.4. CSP accreditation scheme


© 2005 OLAS - Office Luxembourgeois d'Accréditation et de Surveillance

4.5. CSP supervision scheme


© 2005 OLAS - Office Luxembourgeois d'Accréditation et de Surveillance