OpenHSM: An Open key life cycle protocol for Public Key Infrastructure's Hardware Security Modules
- đ¤ Speaker: Jean Martina, Comupter Laboratory, University of Cambridge
- đ Date & Time: Friday 22 June 2007, 16:00 - 16:30
- đ Venue: Computer Laboratory, William Gates Building, Room FW11
Abstract
The private keys used in a PKI are its most important asset. Protect these keys from unauthorised use or disclosure is essential to secure a PKI . Relying parties need assurances that the private key used to sign their certificates is controlled and managed following pre-defined statement policy. Hardware Security Modules (HSM) offer physical and logical protection and should be considered for any PKI deployment. The software that manages keys inside an HSM should control all life cycle of a private key. Normally this kind of equipment implements a embedded key management protocol and this protocols are not available to public scrutiny due to industrial interests. Other important issue is that HSMs are targeted in their development to the Bank industry and not to PKI , making some important PKI issues, like, strict key usage control and a secure auditing trail, play a secondary role. This paper presents an open protocol to securely manage private keys inside HSMs. The protocol is described, analysed and discussed.
Link to the paper: http://www.cl.cam.ac.uk/users/jem74/europki-2007.pdf
Paper continuing the idea: http://www.cl.cam.ac.uk/users/jem74/sbseg2007.pdf
Series This talk is part of the Computer Laboratory Security Group meeting presentations series.
Included in Lists
- All Talks (aka the CURE list)
- bld31
- Cambridge talks
- Computer Laboratory Security Group meeting presentations
- Computer Laboratory, William Gates Building, Room FW11
- Department of Computer Science and Technology talks and seminars
- Interested Talks
- School of Technology
- Security-related talks
- Trust & Technology Initiative - interesting events
- yk449
Note: Ex-directory lists are not shown.
![[Talks.cam]](/static/images/talkslogosmall.gif)


Friday 22 June 2007, 16:00-16:30