Security middleware for enhancing interoperability of Public Key Infrastructure
Research output: Journal Publications and Reviews › RGC 21 - Publication in refereed journal › peer-review
Author(s)
Detail(s)
Original language | English |
---|---|
Pages (from-to) | 535-546 |
Journal / Publication | Computers & Security |
Volume | 22 |
Issue number | 6 |
Online published | 26 Sept 2003 |
Publication status | Published - Sept 2003 |
Externally published | Yes |
Link(s)
Abstract
This paper describes a security middleware for enhancing the interoperability of public key infrastructure (PKI). Security is a key concern in e-commerce and is especially critical in cross-enterprise transactions. Public key cryptography is widely accepted as an important mechanism for addressing the security needs of e-commerce transactions because of its ability to implement non-repudiation. The deployment of public key cryptography is facilitated by the provision of PKI which assures the integrity of cryptographic keys. Nevertheless, industry experiences have shown that the task of implementing PKI-based e-commerce applications is challenging. Prior studies have identified interoperability as a major issue that hinders the adoption of PKI in spite of its effectiveness in implementing strong security mechanisms and protocols. In this paper, we discuss the interoperability issue of PKI applications. This research is part of our effort in designing security infrastructure for e-commerce systems. A middleware architecture was designed to enhance interoperability of PKI applications. The security middleware aims to promote cross-enterprise cross-border e-commerce transactions. The proposed mechanism is proven to be practical in real deployment environment.
Research Area(s)
- Cryptography, Electronic Commerce, PKI, System security
Citation Format(s)
Security middleware for enhancing interoperability of Public Key Infrastructure. / Lam, Kwok-Yan; Chung, Siu-Leung; Gu, Ming et al.
In: Computers & Security, Vol. 22, No. 6, 09.2003, p. 535-546.
In: Computers & Security, Vol. 22, No. 6, 09.2003, p. 535-546.
Research output: Journal Publications and Reviews › RGC 21 - Publication in refereed journal › peer-review