Key Ceremony

Key Ceremony

At the heart of every certificate authority or certification authority (CA) is at least one Root Key(s) or Root Certificate(s) and usually, at least one Intermediate Root Certificate(s). These Digital Certificates are made from a Public and a Private Key. A Root Key Ceremony is a procedure where a unique pair of Public and Private Root Keys is generated. Depending on the Certificate Policy, the generation of the Root Keys may require notarization, legal representation, witnesses and ‘Key Holders’ to be present. 'Best practice' is to follow the SAS70 standard for Root Key Ceremonies.

Examples

Example A: Strong identification & non-repudiation for email & web access

Unless the information being accessed or transmitted is valued in terms of millions of dollars, it is probably sufficient that the Root Key Ceremony be conducted within the security of the vendor's Laboratory. The customer may opt to have the Root Key stored on a Luna Card or HSM, but in most cases, the safe storage of the Root Key on a CD or hard disk is sufficient. The Root Key is never stored on the CA server.

Example B: Machine Readable Travel Document [MRTD] ID Card or e Passport

This type of environment requires much higher security. When conducting the Root Key Ceremony, the Government or Organization will require rigorous security checks to be conducted on all personnel in attendance. Those that are normally required to attend the Key Ceremony will include a minimum of two Administrators from the organization, two signatories from the organization, one lawyer, a notary and two video camera operators, in addition to the CA software vendor's own technical team.

Overview

The actual Root Key-Pair generation is normally conducted in a secure vault that has no communication or contact with the outside world other than a single telephone line or intercom. Once the vault is secured, all personnel present must prove their identity using at least two legally recognized forms of identification. Every person present, every transaction and every event is logged by the lawyer in a Root Key Ceremony Log Book and each page is notarized by the notary. From the moment the vault door is closed until it is re-opened, everything is also video recorded. The lawyer and the two organization’s signatories must sign the recording and it too is then notarized.

Finally, as part of the above process, the Root Key is broken into as many as twenty-one parts and each individual part is secured in its own safe for which there is a key and a numerical lock. The keys are distributed to as many as twenty-one people and the numerical code is distributed to another twenty-one people.

even Principal Components of a Root Key Ceremony

*1. Key Generation Ceremony
*2. Key Ceremony Definition
*3. Key Ceremony Preparation
*4. Root Key Creation
*5. Root Key Activation
*6. Root Key Maintenance
*7. Root Key Recertification

Important Note

Example A and B are at opposite ends of the security spectrum and no two environments are the same. When considering the Root Key Ceremony, CA vendor Team of professional advisors can assist you in deciding on the most efficient level of security to reflect the level of protection required.

Providers

The CA vendors and organisations that would implement projects of this nature where conducting a Root Key Ceremony would be a central component of their service would be organisations like RSA, VeriSign, Digi-Sign and others.

ee also

* SAS 70
* Certificate Authority
* Private Key

External links

*


Wikimedia Foundation. 2010.

Игры ⚽ Нужен реферат?

Look at other dictionaries:

  • Root Key Ceremony — At the heart of every certificate authority or certification authority (CA) is at least one Root Key(s) or Root Certificate(s) and usually, at least one Intermediate Root Certificate(s). These Digital Certificates are made from a Public and a… …   Wikipedia

  • Ceremony (song) — Ceremony Single by New Order B side In a Lonely Place Released 6 March 1981 (19 …   Wikipedia

  • Key (lock) — A cut key A key is an instrument that is used to operate a lock. A typical key consists of two parts: the blade, which slides into the keyway of the lock and distinguishes between different keys, and the bow, which is left protruding so that… …   Wikipedia

  • Japanese tea ceremony — Tea ceremony The Japanese tea ceremony, also called the Way of Tea, is a Japanese cultural activity involving the ceremonial preparation and presentation of matcha, powdered green tea. In Japanese, it is called chanoyu (茶の湯) or chadō ( …   Wikipedia

  • Samoa 'ava ceremony — The ʻaumaga, ava makers must follow etiquette and cultural protocol in the making and serving of the ava. It is usually an honour to be selected for the ceremony. The ʻaumaga, with prescribed roles in the ceremony, were a select guild in the past …   Wikipedia

  • 2006 Commonwealth Games closing ceremony — The Closing Ceremony of the 2006 Commonwealth Games was held at the Melbourne Cricket Ground in Melbourne, Victoria, Australia on March 26, 2006 to mark the closing of the 18th Commonwealth Games.PerformancesThe ceremony began with a fireworks… …   Wikipedia

  • Mound Key Archeological State Park — / Mound Key Site IUCN Category V (Protected Landscape/Seascape) …   Wikipedia

  • Virginia Key — Infobox nrhp name = Virginia Key Beach Park caption = Virginia Key Beach location = Miami, Florida lat degrees = lat minutes = lat seconds = lat direction = N long degrees = long minutes = long seconds = long direction = W area = built =… …   Wikipedia

  • California-Nevada-Hawaii District Key Club International — The California Nevada Hawaii District Key Club International, Cali Nev Ha, or simply CNH is a governing body of Key Club International, a youth sponsored community service organization of Kiwanis International, local Kiwanis clubs and school… …   Wikipedia

  • Mecaru Ceremony — (Me CAR oo) In the Balinese Hindu religion, achieving balance in all things is key, and by making yadnya (holy sacrifices), this goal may be achieved. One such ceremony is called Bhuta Yadnya (the Holy Sacrifice to the Bad Nature Spirits). The… …   Encyclopedia of vampire mythology

Share the article and excerpts

Direct link
Do a right-click on the link above
and select “Copy Link”