Public Key InfrastructureAlnpete has been involved in various organisations use of Public Key Infrastructure since before PKI became fashionable! There are many security consultants advocating the use of PKI as a means of delivering a consistent and effective level of security across an organisation, providing functionality for authentication, integrity and confidentiality to a variety of services. Although the underlying public key cryptographic technology is well-established, having been around since the 1970's, the widespread convergence on a small number of standards (most especially X.509 for certificates and LDAP for directories) has been a more recent innovation, driven largely by the success of the Web and the adoption of X.509 for the certificates underpinning SSL. Suppliers of PKI solutions have enhanced their products to try to deal with the real world problems and challenges that are only now finally being encountered since many early PKI implementations progressed no further than pilots or small scale deployments. Few have been robust enough for large scale, high availability services. However, Alnpete helped design the implementation of perhaps the first effective large-scale commercial PKI in the UK with 100s of thousands of users and a high throughput of transactions requiring high availability and high resilience directory services to enable real-time authentication and signature verification for a variety of online and e-commerce services. More recently, Alnpete has been involved in the design of systems that implement elements of the underlying PKI that underpins the issuance of electronic passports; the design of systems that enable the next generation of EU electronic passports to be inspected, using the additional PKI to assure the authenticity and authority of terminals to read sensitive biometric data and ensuring that critical key material and certificates are appropriately protected; the development of policies, processes and procedures for the establishment, management and operation of a PKI that underpins the processing of financial transactions within a bank, in time to enable the new Faster Payments processing to be supported. Alnpete can bring that experience and expertise to bear on your problems. We can work with you to develop your strategy (everything from the structure of your CA hierarchy to the contents of the CPS), to understand your needs and help you choose an appropriate solution. We are also called on to provide seminars on the underlying concepts and technology. This is crucial for business audiences who need to understand the value that cryptography, PKI and trust services can bring to their organisation; it can also be invaluable for technical audiences who frequently do not have the specialised knowledge and experience to understand the mechanisms that they may be required to rely upon when they implement new services for an organisation. |
|
|||
|
As well as producing a well received and highly influential briefing on Security in Electronic Commerce that established the need for a PKI for a major banking group, Alnpete subsequently provided consultancy to develop the technical and commercial strategy for the development and implementation of the PKI within that group's infrastructure, including a series of White Papers covering the fundamental issues surrounding the use of public key cryptography and online trust services. The PKI was successfully implemented and played a crucial role in securing what became the fastest growing Online Banking Service in the UK. Further online trust services were developed as a result. |
||||
|