Security middleware for enhancing interoperability of Public Key Infrastructure

Research output: Journal Publications and ReviewsRGC 21 - Publication in refereed journalpeer-review

4 Scopus Citations
View graph of relations

Author(s)

  • Kwok-Yan Lam
  • Siu-Leung Chung
  • Ming Gu
  • Jia-Guang Sun

Detail(s)

Original languageEnglish
Pages (from-to)535-546
Journal / PublicationComputers & Security
Volume22
Issue number6
Online published26 Sept 2003
Publication statusPublished - Sept 2003
Externally publishedYes

Abstract

This paper describes a security middleware for enhancing the interoperability of public key infrastructure (PKI). Security is a key concern in e-commerce and is especially critical in cross-enterprise transactions. Public key cryptography is widely accepted as an important mechanism for addressing the security needs of e-commerce transactions because of its ability to implement non-repudiation. The deployment of public key cryptography is facilitated by the provision of PKI which assures the integrity of cryptographic keys. Nevertheless, industry experiences have shown that the task of implementing PKI-based e-commerce applications is challenging. Prior studies have identified interoperability as a major issue that hinders the adoption of PKI in spite of its effectiveness in implementing strong security mechanisms and protocols. In this paper, we discuss the interoperability issue of PKI applications. This research is part of our effort in designing security infrastructure for e-commerce systems. A middleware architecture was designed to enhance interoperability of PKI applications. The security middleware aims to promote cross-enterprise cross-border e-commerce transactions. The proposed mechanism is proven to be practical in real deployment environment.

Research Area(s)

  • Cryptography, Electronic Commerce, PKI, System security

Citation Format(s)

Security middleware for enhancing interoperability of Public Key Infrastructure. / Lam, Kwok-Yan; Chung, Siu-Leung; Gu, Ming et al.
In: Computers & Security, Vol. 22, No. 6, 09.2003, p. 535-546.

Research output: Journal Publications and ReviewsRGC 21 - Publication in refereed journalpeer-review