Strong Authentication and Authorization model Using PKI, PMI, and Directory
Since Internet has been used commonly in information systems technologies, many applications need some security capabilities to protect against threats to the communication of information. Two critical procedures of these capabilities are authenticati on and authorization. This report presents a strong authentication and authorization model using three standard frameworks. They are PKI, PMI, and Directory. Both PKI and PMI are described in X.509 st andard 4th edition. PKI provides a framework to verify the identities of each entities of given domain. The framework includes the requesting, issuing, signing, and validating of the public-key certificates.