ZHAW-Logo OAPA-Logo TAT-Logo
zurück  
Diplomarbeit 2005 (DA05): Arbeits-Archiv
 
DA Rer 05/4 - Public Key Server++
Studierende: Jean-Claude Bandle, bandljea
  Christian Winzeler, winzechr

Betreuer: Marc Rennhard, rema

Today the internet is heavily populated with a lot people using it. It is very easy for someone with access to computers or networks through which your information is traveling to capture this information and read or even manipulate it. Just like someone in the next room listening to your phone conversation. Therefore secure messaging is needed. How can you protect your messages against this threat? The answer lies on Public Key Infrastructure (PKI). PKI is a policy for establishing a security method management system that uses a public or private key to authenticate the identity of people and organizations for the purposes of secure exchange of electronic messages over a public system such as the Internet. Todays popular public key standards are X.509 and Pretty Good Privacy (PGP).

In collaboration with PrivaSphere, a public key server was developed, which enables the user to record public keys. Until now, no public key server was able to handle PGP or X.509 keys. With the Public Key Server ++ it is now possible to save X.509 or PGP public keys from any workplace that has an internet connection. The keys entered are stored and thus can be retrieved at any time. Additionally, the server also allows an export of the stored public keys or they can be deactivated if they are expired.

An additional requirement from PrivaSphere was a "Certificate Class 0" function. This function allows to generate a certificate of class 0, which could be base of a X.509 certificate. The class 0 certificate could be stored on the server, or independend generated as a certificate. These certificates are mainly used for certified authentication. That brings the benefit, that even without username and password, a "Phishing" attack is impossible.

zurück