Anders: PKI has nothing to with trust, and does not even define trust, so your title does not compute.
Perhaps you mean "PKI authorization networks"? Quite often, when people talk about trust they really mean authorization -- but use trust because trust sounds better ;-) Cheers, Ed Gerck Anders Rundgren wrote: > Survey regarding the future of PKI trust networks > ------------------------------------------------------ > > Traditionally certificates have been purchased (or just issued) for > an entity by a party that is concerned that the entity can be properly > identified in authentication- and signature-operations. > > For a relying party (RP) to check certificate-status has mostly been a > public and free service. > > The financial industry however, have in several recent PKI-ventures > shown that they intend to change this by treating lookup-services as > equivalent to payment transactions, where the RP's bank is used as a > "trust clearing center" communicating with the subscriber's bank that > must be a member of the same "trust network". To make it technically > impossible for RPs to fully verify signatures without going through > the trust network (and paying for the services), root-certificates are > usually not "published". > > I would be very happy to hear what the PKI community in general > think about this scheme as the future for PKI. Off-list responses > will be treated as CONFIDENTIAL information. > > Anders Rundgren
