PKI & Digital Certificates Explained: Solving the "Trust" Problem in Cryptography

 

HELLO FRIENDS

WELCOME TO MY CYPHER LOG 

   Guys today we are going to see about the public key infrastructure and digital certificates. It plays the main role in keeping people away from fake organisations.

LET'S DIVE INTO THE TOPIC

PUBLIC KEY INFRASTRUCTURE

   We have already seen the public key in cryptography, actually it is a system that combines both public key and real world identity and it acts like a backbone of secure internet browsing.

THE DIGITAL CERTIFICATE

     We all have physical documents like our birth certificate and national Id cards there is a sign of a higher authority and we use those certificates to prove our identity right that's how this digital certificate works for websites and organisations.
If we receive any email or SMS we would like to see the header like we have already seen about that in our past blogs, actually we see that to know is that the real message from the real organisation.
Organisation would have a registered address as a Digital certificate and claim their ownership to the website and it contains an entity's name, entity's public key and the digital signature of the issuer and also an expiring date in that.

THE CERTIFICATE AUTHORITY

The digital certificate will be valid if the certificate authority has signed that.
CA is the highly secure and trusted organisation and they would likely check the entity's identity before issuing a certificate to them.

THE TRUSTED CHAIN OF PKI

It has three stages which is Root CA, Intermediate CA, End entity certificate.

THE ROOT CA

    The root CA is which is we all using daily which is Microsoft, Apple, Google Play Store to install applications. It is a self signed authority.

INTERMEDIATE CA

  The root CA's won't directly provide the digital certificates to the websites because of security reasons there where the intermediate CA works, the root CA's would issue certificate to intermediate CA and and it would be issued to the claimed website.

THE END ENTITY CERTIFICATE

   The certificate will installed on the actual website of the organisation or the user who claimed the ownership of the website.

If there were any scams that happened investigators would check if the user, your connection is not private and they clicking the proceed anyway button actually it happens because attackers creating their self signed certificates and the CA browsers would consider it as a redflag and give us warning.
There is a possibility of compromised CAs too but it's rare attackers might breach a CA and claim a certificate looking legitimate and it allows man in the middle attack.

REVOCATION

   If a private key is stolen the CA must invalidate the certificate.

so thats it guys these are things I have learned today, I hope you guys understood it.

if you want study guide to know more you can get through this link.

THANK YOU

Comments

Popular posts from this blog

Day 2: Understanding the CIA Triad, AAA

Cryptography Basics: Encryption Types & Hashing Explained

Cyber Security Day 4: Understanding Layered Security & Defence in Depth