Public Key Infrastructure

Understanding Public Key Infrastructure (PKI)

  • The term Public Key Infrastructure (PKI) refers broadly to:

    • Policies and procedures related to cryptography.

    • Hardware and software involved in:

    • Creating digital certificates

    • Distributing certificates

    • Managing certificates

    • Storing certificates

    • Revoking certificates

    • Other associated processes.

  • Importance of PKI:

    • Involves considerable planning even for small organizations.

    • Decisions must be made regarding encryption methods and application within the organization.

    • PKI is often linked with a Certificate Authority (CA), which helps establish trust concerning individuals or devices.

Symmetric Encryption

  • Definition: Symmetric encryption uses the same key for both encrypting and decrypting data.

  • Metaphor: The symmetric key is often compared to a secret key kept in a suitcase, which is handcuffed to a deliverer, ensuring its security.

  • Key Characteristics:

    • If someone possesses the symmetric key, they can decrypt data encrypted with it.

  • Alternate Terms:

    • Secret Key Algorithm: Used to refer to the symmetric key’s role in encryption/decryption.

    • Shared Secret: Indicates that the same key is utilized for both processes.

  • Scalability Problem:

    • Distributing the symmetric key to multiple users becomes complex and unmanageable as the number of users increases.

    • Once there are more than 10 individuals or devices, sharing and managing keys becomes difficult.

  • Use Cases:

    • Still commonly used due to speed and low overhead compared to asymmetric encryption.

Asymmetric Encryption

  • Definition: Asymmetric encryption involves two mathematically related keys:

    • One key for encrypting (public key)

    • Another key for decrypting (private key).

  • Key Generation: Both keys are created simultaneously through a mathematical process.

  • Key Characteristics:

    • The private key is restricted to one person/device; it must remain secret.

    • The public key is openly available and can be shared with anyone.

  • Functionality:

    • Anyone can encrypt data using the public key.

    • Only the holder of the private key can decrypt the data encrypted with the corresponding public key.

  • Example:

    • Individuals such as Bob may encrypt messages using Alice's public key. Only Alice, possessing the private key, can decrypt it.

  • Mathematical Relationship:

    • No one can derive the private key from the public key due to complex mathematical algorithms, ensuring security.

Key Generation Process

  • Process: Key generation typically involves the use of:

    • Randomization techniques

    • A combination of large prime numbers.

  • One-Time Setup: Users usually need to generate their public-private key pair only once.

  • Example Case: Alice generates a key pair:

    • Outputs:

    • Public Key: Can be shared widely.

    • Private Key: Should be stored securely, often with an assigned password for protection.

Practical Example of Asymmetric Encryption

  • Bob wants to send Alice a secured message.

    • Plaintext Message: "Hello, Alice".

    • Bob uses Alice's public key to encrypt the plaintext, creating ciphertext.

  • Sending the Ciphertext:

    • The encrypted data can be shared without revealing the underlying message.

    • Even with access to the ciphertext and public key, no one can decrypt it without Alice's private key.

  • Decryption Process:

    • Alice receives the ciphertext and uses her private key to recover the original message.

Key Management Considerations

  • User Management:

    • Individuals typically manage their own public-private key pairs.

    • In larger environments, key management becomes crucial due to the number of keys.

  • Options for Key Management:

    • You might use a third-party service to maintain private keys.

    • Alternatively, you can implement key escrow for local storage and management of keys.

  • Need for Data Accessibility:

    • If a user leaves the organization, access to their encrypted data must still be maintained by retaining the associated private keys.

    • Possible scenarios include collaboration with external partners or managing sensitive organizational data across departments.

  • Ethical Considerations:

    • Handing over private keys may raise ethical concerns. However, it may be necessary to ensure continuous access to data and maintain operational integrity of the organization.