Exploring the Role of Certificate Authorities and Registration Authorities in a PKI
One central tenet behind the use of a PKI and trusted third-party protocols is that all participating parties agree to accept the word of a neutral third party. Should two parties need to validate each other, they turn to this trusted third party, which in turn provides in-depth authentication of the parties involved. This is done rather than having each party perform its own authentication.
These entities rely on the third party (the CA) to conduct an in-depth investigation of each entity before any credentials are issued. Furthermore, these entities rely on this trusted third party to issue credentials that are extremely difficult to forge. With these "assumptions" in place, from this point forward, all individuals who trust the third party agree to readily accept the credentials that it issues. If any of these assumptions are incorrect, the validity of this process is called into question, and the security of all entities is at risk.
Because of networking constraints, processor overhead, and general practicality, it is not reasonable for all parties in a large organization to continuously exchange identification documents for all communications. If you think about it, this is not that different from how your own organization may approach measures of physical security.
For example, you may work for an organization that issues each employee an ID badge. Before someone is given an employee badge, various measures probably are taken in conjunction with general hiring procedures. Perhaps a background check is run, or documentation is collected, such as a copy of the employee's driver's license and birth certificate, to ensure that the employee is who he claims to be. As soon as the employee passes this authentication process, he receives his employee badge. Of course, in addition to these authentication steps, the badge itself is made in such a way that it would be difficult to duplicate or forge. This adds another layer of trust. After the badge is issued, it is accepted as proof of the individual's identity and authority to work within your organization.
You might be wondering what would provide this validation if you did not have a process such as this in place. Let's assume that ten individuals within the organization need to validate each other, and there is no trusted third-party proof of identity, such as company ID badges. What might be involved? If no trusted third party is in place, this process of ten individuals validating each other would result in 90 separate validations before everyone would have validated everyone else. If that sounds messy, consider adding just one more individual to the group. This single addition would require an additional 20 validations, because each of the original group of ten individuals would need to authenticate the new person, and then the new person would need to authenticate the original ten. As you can see, this approach does not scale well. It becomes practically impossible for organizations of considerable size.
Certificate servers act as this trusted third party so that entities can provide the utmost level of trust between themselves, without the time-consuming complexities that would be involved if each individual entity needed to directly validate the others. As the example indicates, this would be impractical.
Continue reading here: Examining Identity Management
Was this article helpful?