To read this content please select one of the options below:

Outsourcing digital signatures: a solution to key management burden

Dimitrios Lekkas (Department of Product and Systems Design Engineering, University of the Aegean, Syros, Greece)
Costas Lambrinoudakis (Department of Information and Communication Systems Engineering, University of the Aegean, Samos, Greece)

Information Management & Computer Security

ISSN: 0968-5227

Article publication date: 1 October 2006

2135

Abstract

Purpose

Digital signatures are only enjoying a gradual and reluctant acceptance, despite the long existence of the relevant legal and technical frameworks. One of the major drawbacks of client‐generated digital signatures is the requirement for effective and secure management of the signing keys and the complexity of the cryptographic operations that must be performed by the signer. Outsourcing digital signatures to a trusted third party would be an elegant solution to the key management burden. Aims to investigate whether this is legally and technically feasible.

Design/methodology/approach

In this paper's approach a relying party trusts a Signature Authority (SA) for the tokens it issues, rather than a Certification Authority for the certificates it creates in a traditional public key infrastructure scheme.

Findings

The paper argues that passing the control of signature creation to a SA rather than the signer herself, is not a stronger concession than the dependence on an identity certificate issued by a Certification Authority.

Originality/value

The paper proposes a framework for outsourced digital signatures.

Keywords

Citation

Lekkas, D. and Lambrinoudakis, C. (2006), "Outsourcing digital signatures: a solution to key management burden", Information Management & Computer Security, Vol. 14 No. 5, pp. 436-449. https://doi.org/10.1108/09685220610707449

Publisher

:

Emerald Group Publishing Limited

Copyright © 2006, Emerald Group Publishing Limited

Related articles