Roger Schell, Creating PKI You Can Trust (July 18, 2001)

Опубликовано: 12 Октябрь 2024
на канале: securitylectures
314
2

From the CISR video library (http://www.cisr.us)

Roger Schell, President and COO of Aesec
Creating a PKI You Can Trust
July 18, 2001

at the
Naval Postgraduate School
(http://www.nps.edu)

ABSTRACT
Conducting business has always required some degree of trust.Conducting e-business introduces a need to allocate more and more of this trust to technology. An entire industry engaged in building a "Public Key Infrastructure" (PKI) has grownup around the promise of providing technology for e-business.Unfortunately, much of what is currently offered does not meet real business needs for trust. Dr. Schell will present some results from the business community examining the question of how a PKI can enable e-business. He concludes that interoperability and liability allocation require a high integrity root of trust that is common between the engaging parties, as well as digital certificates containing an explicit quality attribute that can be reliably used to make informed local decisions on the suitability of a certificate for a particular business process. Perhaps his most significant conclusion is that in order for PKI technology to be trusted, digital certificates should be produced on and consumed by platforms having an explicit measurable assurance of the platform's correct security behavior.

About Roger Schell

Dr. Roger R. Schell is President and COO of Aesec, a new company focused on appliances built on hardened platforms for secure, reliable e-business on the Internet. For several years he managed the successful development and delivery of security for several Novell releases of network software products including an integral PKI, an international crypto API and an authentication service with exposed SSL capability. Dr. Schell was co-founder and Vice President for Engineering of Gemini Computers, Inc.,where he directed development of their highly secure (Class A1)network processor commercial product. He was also the founding Deputy Director of the DoD (now National) Computer Security Center. Previously he was an Associate Professor of Computer Science at the Naval Postgraduate School.

Dr. Schell is a retired USAF Colonel. He received a Ph.D. in Computer Science from the MIT, an M.S.E.E. from Washington State,and a B.S.E.E. from Montana State. He originated several key modern security design and evaluation techniques and holds patents in cryptography and authentication. He is widely regarded as the "father" of the Trusted Computer System Evaluation Criteria (the "Orange Book"). The NIST and NSA have recognized Dr. Schell with the National Computer System Security Award, the nation's highest honor in the information security field.