PKI for IoT
Create and manage electronic certificates with PKI for IoT
Electronic certificates allow applications to support security services such as user authentication, non-repudiation of transactions and confidential data exchanges.
Atos, a European actor in IS security, provides PKI for IoT, a complete solution to create and manage electronic certificates for your IoT infrastructure, and manage the connected devices lifecycle.
Strong internal security
MetaPKI ensures data security, including strong authentication to access all MetaPKI functional entities, recording of all actions, encrypted sensitive information, and private and public keys protected using hardware security modules (HSM).
Certifications
MetaPKI is EAL 3+ Common Criteria Certified and is also RGS basic level certified
Performance
Produce 1,000+ certificates per second in specific formats like C-ITS certificates for car-to-car communication
n-Tier architecture and scalability
- 3-Tier architecture: Front office, back office and external databases
- Scalability: Capability to add several front offices and/or several back offices
Automation and auto-enrollment protocols (CMP, SCEP, EST)
- CMP and SCEP already available for X509 certificates
- EST in progress for X509 certificates and other formats
Support for Long-Term CA (X509 certificates with RSA or ECDSA keys), Pseudonym CA (X509 certificates with RSA or ECDSA keys), and short-lived pseudonym certificates (C-ITS) (Specific certificates with ECDSA keys).
Performance
- Capacity to produce over 1,000 certificates/second in specific formats (like C-ITS certificates)
System requirements
- Linux Platform (e.g. Red Hat or SUSE)
- Open source international components delivered with MetaPKI: Apache, OpenSSL, PostgreSQL and PHP
- LDAP Server: when the CA publishes certificates and/or LCR in a directory
- SMTP Mail Server: when MetaPKI sends notifications related to the management of certificates
Norms and standards
- Certificate compliance with ITU-T X.509v3 and RFC 5280
- Certificate enrollment protocols: SCEP, CMP (RFC 2510 et RFC4210), CCEP
- Certificate profile compliance with ETSI TS 101 862, Netscape and Microsoft
- Revocation information compliance with ITU-T X.509v2 LCR and OCSP Protocol (RFC 2560)
- Certification request format: PKCS#10, SPKAC
- Key exchange format: PKCS#12
- Connectivity: LDAP, HTTPS, SMTP
- HSM interface: PKCS#11
Environment
Hardware and software for MetaPKI hosting
- Physical Servers: 32/64 bits platform with at least 4 Go of RAM, 10 Go of available disc memory, 2 Ethernet ports
- Virtual Machines: VMWare, HyperV
- Operating System: Red Hat 5 and 6 (32 or 64 bits) / SUSE SLES 10 and 11 (32 or 64 bits)
- LDAP Server: CAs publish the certificates and/or the LCR in a LDAP directory
- Mail Server: Email sending is possible for each step of certificates life cycle
Workstations for MetaPKI users
- Browser: Internet Explorer 8 version and later, Firefox, Chrome
- Java Runtime Environment: 1.6 (superior to update 19), 1.7 et 1.8
Smart Card
- All smart cards with PKCS#11 interface and particularly: CardOS, Gemalto ID PRIME MD840, Gemalto IAS TPC, Gemalto Classic TPC IM, Gemalto Cyberflex Access 64k v2, Morpho vpsID SmartCard Ux, ActivIdentity ActivCard 64K V2C
HSM
- All HSM with PKCS#11 interface and particularly Bull TrustWay Proteccio®
Electronic certificates may be used to support:
Users and applications are provided with one or more key pairs (a public key and a private key) and public key certificates, generated by a Certification Authority (CA), that associate the registered user or application with the public key.
MetaPKI supports one or more Certification Authorities that may be independent, or subordinate CAs.
A whole range of security profiles for public certificates is supported by MetaPKI. For each profile, the registration process may be tailored to the specific needs of the organization and integrated with the existing IS.
A workflow manager handles the registration process in order to minimise the time to produce and manage the certificates through the use of one or more Local Registration Authorities (LRA).
A validation authority (Vericert) for checking the validity of a certificate against a validation policy
Related resources and news
IoT Security Suite
Build trusted and secure Intelligent Transportation Systems
Secured V2X communication is critical to set up reliable ITS. Discover how PKI solutions are the key to securing exchanges between connected vehicles and roadside units.
Bring trust to Intelligent Transportation Systems with a cybersecurity and standardization approach.