Glossary · OT cybersecurity
Public key infrastructure (PKI)
Also known as: PKI
German: Public-Key-Infrastruktur (PKI)
In cryptography, a public key infrastructure (PKI) is the set of roles, policies, procedures and systems needed to create, manage, distribute, store and revoke digital certificates that bind public keys to identities. It includes certificate authorities, registration processes, certificate repositories and revocation services.
- OT security
In one sentence
A public key infrastructure (PKI) is the set of roles, policies and systems that issue, manage and revoke digital certificates binding keys to identities.
Example
The company's PKI issues certificates for web servers, VPN gateways and signed documents, with a two-tier hierarchy of an offline root CA and an online issuing CA.
How it applies
- Engineering: A PKI enables authentication without shared passwords, encrypted connections and signatures on software and documents. Certificates usually follow ITU-T X.509; the internet profile is described in RFC 5280.
- Operation: Certificate policies define key lengths, lifetimes, who may request which certificate and how identities are checked. Revocation lists or online status services tell relying parties which certificates are no longer valid.
- Maintenance: Root and issuing CA keys need strong protection. A plan for CA compromise and key rollover must exist before it is needed.
- Documentation: Certificate policies and practice statements are controlled documents. Product and system documentation should explain which PKI functions a product supports (certificate formats, enrollment, revocation checking).
PKI vs. encryption
Encryption protects data. A PKI solves the trust problem behind it: it lets a party verify that a public key really belongs to the device or person it claims to belong to.