25.02.2013 Views

TCP/IP Tutorial and Technical Overview - IBM Redbooks

TCP/IP Tutorial and Technical Overview - IBM Redbooks

TCP/IP Tutorial and Technical Overview - IBM Redbooks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Key management on such a large scale requires something beyond a simple, flat<br />

certification structure. The organization of certifying authorities proposed for SET<br />

is shown in Figure 22-57.<br />

Cardholder<br />

Cardholder<br />

Cardholder CA<br />

CA<br />

CA<br />

Cardholder<br />

Figure 22-57 SET certifying authorities<br />

At the top of the certificate chain, the root certifying authority is to be kept offline<br />

under extremely tight arrangements. It will only be accessed when a new credit<br />

card br<strong>and</strong> joins the SET consortium. At the next level in the hierarchy, the br<strong>and</strong><br />

level CAs are also very secure. They are administered independently by each<br />

credit card br<strong>and</strong>.<br />

There is some flexibility permitted under each br<strong>and</strong> for different operating<br />

policies. It would be possible to set up CAs based on region or country, for<br />

example. At the base of the CA hierarchy are the CAs that provide certificates for<br />

merchants, cardholders, <strong>and</strong> acquirer payment gateways. The SET specification<br />

provides protocols for merchants <strong>and</strong> cardholders to request certificates online. It<br />

is important to have a simple process because SET aims to encourage<br />

cardholders to have their own certificates. It envisions the cardholder surfing to<br />

the CA Web site, choosing a Request Certificate option to invoke the certificate<br />

884 <strong>TCP</strong>/<strong>IP</strong> <strong>Tutorial</strong> <strong>and</strong> <strong>Technical</strong> <strong>Overview</strong><br />

Root<br />

CA<br />

Br<strong>and</strong><br />

CA<br />

Geo-Political CA<br />

(optional)<br />

Cardholder<br />

Cardholder<br />

Merchant CA<br />

CA<br />

CA<br />

Merchant<br />

Cardholder<br />

Cardholder<br />

Payment CA<br />

CA<br />

CA<br />

Acquirer<br />

Gateway<br />

MasterCard

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!