Public Key Infrastructure (PKI) provides the technology and trust framework behind modern digital signatures. It uses public and private key cryptography to securely identify users, sign electronic documents and verify digital transactions.
Public Key Infrastructure is a framework used for the creation, issuance, storage, management and verification of digital certificates. PKI connects a public key with the identity of an individual, organization or system and provides the foundation required for trusted electronic communication and digital signing.
PKI combines cryptographic technology, certificates, trusted authorities and management processes to establish secure digital identities.
PKI uses a pair of mathematically related keys. The private key is kept confidential by its owner and is used for digital signing or other protected operations, while the public key can be used to verify signatures or establish secure communication.
A digital certificate associates a public key with verified identity information. It enables systems and users to establish trust when validating a digital signature or communicating securely.
A complete PKI environment includes trusted authorities, identity verification mechanisms, certificate repositories and policies that control how digital certificates are issued, managed, renewed and revoked throughout their lifecycle.
Different components work together to create a trusted environment for digital identity and electronic signing.
The Certificate Authority issues and manages digital certificates and acts as a trusted authority within the PKI environment.
The Registration Authority performs applicable identity verification and assists with certificate enrollment and issuance processes.
A secure repository can be used to store and make relevant certificate information available for validation and management purposes.
Certificate lifecycle processes include enrollment, issuance, renewal, suspension and revocation where applicable.
PKI manages digital identity from certificate application through verification and eventual renewal or revocation.
The applicant's identity is verified according to the applicable certificate issuance procedure before a digital certificate is issued.
After successful verification, the Certificate Authority issues a digital certificate containing relevant identity and public key information.
The certificate holder uses the associated private key to create digital signatures on supported electronic documents and transactions.
Signatures can be verified using the public key and certificate information. Certificates may also be revoked when required under the applicable policy.
The private key is a critical part of PKI and should remain under the control of the authorized certificate holder. It should never be disclosed or shared with unauthorized users.
The public key can be used by a relying party to verify a digital signature and establish a relationship between the signature and the corresponding digital certificate.
Simple public-key infrastructure approaches trust and authorization differently from traditional certificate based PKI models.
Simple Public-Key Infrastructure, commonly associated with SPKI, focuses on authorization and the trust relationship of keys rather than relying primarily on certificates that associate keys with personal identities. In this model, authorization can be integrated directly into the key-based trust system.
PKI technology supports security and authentication across email, documents, applications, websites and communication systems.
PKI can support encryption and sender authentication for secure email communication using technologies such as S/MIME and other certificate-based systems.
Digital certificates and cryptographic keys can be used to digitally sign or encrypt electronic documents and protect their authenticity and confidentiality.
PKI can authenticate users to applications, networks and secure systems using certificates, smart cards and other cryptographic credentials.
Certificate-based security is used to establish trust and secure communication channels between users, browsers, servers and online services.
Public-key cryptography can help bootstrap secure communication protocols by establishing initial trust before protected data exchange takes place.
Mobile signature solutions can use digital signing and certification services to enable secure electronic signatures through mobile and remote environments.
The following flow provides a simple overview of how certificate-based trust can work in a digital transaction.
A public and private key pair is generated for the required cryptographic operation.
The applicable certificate authority process validates identity and issues the digital certificate.
The private key can be used for digital signing while PKI technologies can also support secure encryption.
The recipient or relying system uses certificate and public-key information to validate the transaction.
The security of a PKI environment depends heavily on the protection of private keys and proper certificate management. Private keys should be stored securely and access should be restricted to authorized users. Lost, compromised or incorrectly managed credentials can affect the security of digitally signed transactions.
A properly implemented PKI environment helps organizations establish trusted identities and secure electronic communication.
Certificates help establish a trusted relationship between public keys and verified identities within supported PKI environments.
Public-key cryptography provides the foundation for digital signatures, authentication and secure electronic communication.
A Certificate Authority is a trusted entity responsible
for issuing and managing digital certificates according
to its applicable certificate policies and procedures.
Visit CCA Website →
Effective PKI management includes certificate enrollment, validation, renewal, secure storage and revocation. Organizations should follow the applicable certificate policies and security procedures throughout the certificate lifecycle.
PKI provides the cryptographic foundation required for trusted digital identities, electronic signatures, authentication and secure communication across modern digital systems.