Dartmouth Researchers Continue Pushing Standard To Streamline PKI Verification

Dartmouth College researchers who were pioneers in Public Key Infrastructure (PKI)--a system that secures and authenticates computer communications--are now playing leading roles in establishing Internet standards and guidelines for security. A system developed at the Hanover, NH-based college, called PRQP (which stands for PKI Resource Query Protocol), has been wending its way through the standards body Internet Engineering Task Force since 2006 as a way to more easily implement PKI-enhanced computing security.

"PRQP, very simply, provides a more distributed system for PKI; it works in a way to get trustworthy references in order to verify the PKI certificates of individuals or servers," said Massimiliano "Max" Pala, research fellow with ISTS and the Open Certificate Authority Lab director.

As PKI becomes ubiquitous, IT professionals could in the future presumably rely on PQRP standards-based products to operate PKI efficiently, therefore ensuring a consistent and robust measure of security.

"PKI labors under the misconception that it's difficult," said Scott Rea, senior PKI architect at Dartmouth. "PKI is most successful when it runs under the covers or in the background." And that's what it does on a lot of commercial Web sites that accept credit card numbers, ensuring security behind-the-scenes using PKI or "certificate authority" technology.

Dartmouth's Institute for Security, Technology, and Society has received funding from the Department of Homeland Security to explore ways to make PKI more user-friendly, for individuals and for businesses of all sizes. That's how PRQP was born.

According to Pala and Rea, adoption of PKI is growing, and there is a deliberate program to bring more and more organizations into the PKI fold. Consortiums have been established, grouped around common themes, so that all members within each group can trust each other's PKI certificates. For example, there are eight organizations now in the Higher Education Bridge Certificate Authority (HEBCA), which was formed to facilitate trusted electronic communications within and between institutions of higher education as well as with federal and state governments. Rea serves as director of the HEBCA Operating Authority and secretary of the HEBCA Policy Management Authority.

There are also bridges for federal employees and contractors, pharmaceutical companies and researchers, and defense and aerospace companies and contractors. All four existing bridge organizations have formed a "federation" to trust everyone within these networks at varying levels. Among all four bridges, about 15 million certificates have been issued (mainly to individuals, but servers and other network devices can also carry certificates). That figure is expected to double in the next 12 to 18 months. Dartmouth alone has 34,000 active certificates; the Dartmouth PKI has issued about 1,500 server certificates.

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • student reading a book with a brain, a protective hand, a computer monitor showing education icons, gears, and leaves

    4 Steps to Responsible AI Implementation

    Researchers at the University of Kansas Center for Innovation, Design & Digital Learning (CIDDL) have published a new framework for the responsible implementation of artificial intelligence at all levels of education.

  • glowing digital brain interacts with an open book, with stacks of books beside it

    Federal Court Rules AI Training with Copyrighted Books Fair Use

    A federal judge ruled this week that artificial intelligence company Anthropic did not violate copyright law when it used copyrighted books to train its Claude chatbot without author consent, but ordered the company to face trial on allegations it used pirated versions of the books.

  • server racks, a human head with a microchip, data pipes, cloud storage, and analytical symbols

    OpenAI, Oracle Expand AI Infrastructure Partnership

    OpenAI and Oracle have announced they will develop an additional 4.5 gigawatts of data center capacity, expanding their artificial intelligence infrastructure partnership as part of the Stargate Project, a joint venture among OpenAI, Oracle, and Japan's SoftBank Group that aims to deploy 10 gigawatts of computing capacity over four years.

  • laptop displaying a phishing email icon inside a browser window on the screen

    Phishing Campaign Targets ED Grant Portal

    Threat researchers at cybersecurity company BforeAI have identified a phishing campaign spoofing the U.S. Department of Education's G5 grant management portal.