SSCP Systems Security Certified PractitionerCryptographyHard

A security architect is designing a system that requires users to have unique, verifiable identities without relying on a centralized Certificate Authority. The goal is to allow users to generate and manage their own keys and certificates in a distributed trust model. Which cryptographic concept best describes this design principle?

  1. ABridge CA
  2. BWeb of Trust
  3. COnline Certificate Status Protocol (OCSP)
  4. DHierarchical PKI
Show answer & explanation

Correct answer: B. Web of Trust

A Web of Trust model (e.g., PGP) allows users to establish trust relationships directly with each other by signing each other's public keys, eliminating the need for a single, centralized CA. This aligns with the requirement for a distributed trust model where users manage their own keys and certificates.

Why the other options are wrong

  • A. A Bridge CA connects different hierarchical PKIs, but still involves CAs and a centralized element.
  • C. OCSP is a protocol for checking certificate revocation status; it's not a trust model for identity verification without a CA.
  • D. Hierarchical PKI is a centralized model with a root CA and subordinate CAs.

Web of Trust (WoT)

A decentralized trust model where individuals directly attest to the authenticity of other users' public keys, rather than relying on a single Certificate Authority.

  • Users sign each other's public keys.
  • No central root of trust.
  • Used by PGP (Pretty Good Privacy) and GPG.

Memory trick: Trust can be a pyramid (PKI) or a spiderweb (Web of Trust).

More Cryptography questions