PKI White Papers
PorKI: Making User PKI Safe on Machines of Heterogeneous Trustworthiness
Overview As evidenced by the proliferation of phishing attacks and keystroke loggers, everyone knows that human beings are not well-equipped to make trust decisions about when to use their passwords or other personal credentials. Public key cryptography can reduce this risk of attack, because authentication using PKI is designed to not give away sensitive data. However, using private keys on standard platforms exposes the user to "Keyjacking"; mobile users wishing to use keypairs on an unfamiliar and potentially untrusted workstation face even more obstacles. This paper presents the design and prototype of PorKI, a software application for mobile devices that offers an alternative solution to the portable key problem.
| Publisher | Dartmouth College | File Format | |
|---|---|---|---|
| Date Published | October 2005 | ||
| Format | White Papers | ||
| Topics | |||
The Ephemerizer: Making Data Disappear
This paper is about how to keep data for a finite time, and then make it unrecoverable after that. It is difficult to ensure that data is completely destroyed. To...
A Public-Key Cryptographic Processor for RSA and ECC
This paper describes an extension to a general-purpose processor for accelerating public-key cryptosystems. Supported are the legacy cryptosystems RSA and DH as well as the newly emerging Elliptic Curve Cryptography...
What's New in Netegrity SiteMinder 5.0: An Overview of New Features
This whitepaper offers an in-depth look at the new SiteMinder 5 features including: eTelligent Rules, Advanced Management and Microsoft support.
Personal Authentication and the PKI Security Process – Benefits of the iKey
Swipe cards, such as credit cards and cards used in automated teller machines (ATMs), contain user information that the authentication program can read to establish the user’s identity. When combined...
SAML Artifact Profile as an Adopted Scheme for E-Authentication
As part of the President's Management Agenda, the E-Authentication Initiative has been established to enable trust and confidence in E-Government transactions via the establishment of an integrated policy and technical...



