Maurizio Adriano Strangio



The European Commission Directive 1999/99/EC aims to provide a community-wide framework for the use of electronic signatures and thus for promoting electronic trade and communication among the member states. The directive introduces the notion of “qualified” digital certificates as a means to maintain legal effects of digital data that are analogous to those of paper-based signatures. To this end, proofs of (physical) identity and possession (of the private key) are fundamental requirements that must be fulfilled by the requester during the public key enrollment process. Digital signatures are often employed as secure buildings blocks in key agreement protocols that use public key authentication. The need for the rigorous analysis of such protocols has recently emerged; there are currently several formal models of distributed computing that may serve for this purpose. However, we point out these models employ rather trivial or unpractical approaches in the modeling of the procedures and policies employed by certification authorities. We believe that usage of qualified certificates not only should represent the standard practice for CAs in order to sustain secure electronic commerce (and in general all forms of secure communication) but also represents the first step towards the domain of a global PKI.


