SSCP Systems Security Certified PractitionerCryptographyHard
A security architect is designing a system that requires users to have unique, verifiable identities without relying on a centralized Certificate Authority. The goal is to allow users to generate and manage their own keys and certificates in a distributed trust model. Which cryptographic concept best describes this design principle?
- ABridge CA
- BWeb of Trust
- COnline Certificate Status Protocol (OCSP)
- DHierarchical PKI
Show answer & explanationAnswer & explanation
Correct answer: B. Web of Trust
A Web of Trust model (e.g., PGP) allows users to establish trust relationships directly with each other by signing each other's public keys, eliminating the need for a single, centralized CA. This aligns with the requirement for a distributed trust model where users manage their own keys and certificates.
Why the other options are wrong
- A. A Bridge CA connects different hierarchical PKIs, but still involves CAs and a centralized element.
- C. OCSP is a protocol for checking certificate revocation status; it's not a trust model for identity verification without a CA.
- D. Hierarchical PKI is a centralized model with a root CA and subordinate CAs.
Web of Trust (WoT)
A decentralized trust model where individuals directly attest to the authenticity of other users' public keys, rather than relying on a single Certificate Authority.
- Users sign each other's public keys.
- No central root of trust.
- Used by PGP (Pretty Good Privacy) and GPG.
Memory trick: Trust can be a pyramid (PKI) or a spiderweb (Web of Trust).