Key Concepts & Self-Assessment20 Key Facts
Review key Public Key Infrastructure (PKI): X.509 Digital Certificates, Certificate Authorities & India’s CCA exam facts and rate your mastery to track revision.
Progress: 0/20 Rated 0 Mastered 0 Review Later
#1
Public Key Infrastructure binds cryptographic public keys to validated real-world identities, resolving the man-in-the-middle problem across open global computer networks.
#2
British GCHQ researchers James Ellis, Clifford Cocks, and Malcolm Williamson conceptualized non-secret asymmetric encryption prior to Diffie and Hellman's 1976 civilian discovery.
#3
Asymmetric systems rely on mathematically linked key pairs where content encrypted by a public key requires the matching secret private key for decryption.
#4
The International Telecommunication Union standardized the X.509 format in 1988, defining mandatory digital certificate fields including serial numbers, subject names, and cryptographic signatures.
#5
A Certificate Authority acts as a trusted third party verifying identity credentials before digitally signing and distributing leaf certificates across client systems.
#6
Registration Authorities conduct identity proofing and background validation of certificate applicants before directing Certificate Authorities to generate signed cryptographic credentials.
#7
The hierarchical chain of trust originates at a self-signed Root Certificate Authority, descending through intermediate authorities to protect end-entity leaf certificates.
#8
Root private keys are maintained offline inside tamper-resistant Hardware Security Modules to protect the global chain of trust from external network compromises.
#9
Public Key Infrastructure enforces confidentiality through transport encryption, data integrity via hashing, identity authentication, and legal non-repudiation of signed digital transmissions.
#10
Certificate Revocation Lists publish periodic rosters of invalidated certificates, enabling relying software applications to identify and reject prematurely cancelled digital credentials.
#11
The Online Certificate Status Protocol provides real-time validation checks, whereas OCSP stapling allows web servers to deliver cached CA validation directly to browsers.
#12
Chapter VI of India's Information Technology Act of 2000 establishes the statutory framework governing digital signatures and licensed certifying authority operations.
#13
The Controller of Certifying Authorities operates under the Ministry of Electronics and Information Technology to regulate and license Indian digital certificate authorities.
#14
The Root Certifying Authority of India digitally signs public key certificates issued to licensed authorities, maintaining national sovereign cryptographic validation standards.
#15
Prominent licensed Indian Certifying Authorities include eMudhra, National Informatics Centre, IDRBT, CDAC, and NSDL, delivering authentication across banking and tax platforms.
#16
Digital Signature Certificates in India are classified into distinct validation assurance tiers, with Class 3 providing the highest commercial and statutory security.
#17
The Indian Information Technology Act grants secure electronic records and authenticated digital signatures evidentiary equivalence to physical handwritten ink documents in courts.
#18
Aadhaar-based eSign enables remote paperless authentication, generating short-lived cryptographic certificates managed by licensed Certifying Authorities for citizen public utility services.
#19
Modern Transport Layer Security protocols utilize Public Key Infrastructure during handshakes to authenticate server certificates and negotiate ephemeral symmetric session keys securely.
#20
Certificate Transparency logs mandate public append-only cryptographic tracking of issued certificates, exposing rogue or mistakenly authorized domains across global internet browsers.
Subject Specialist Commentary
Analytical perspective & practical exam advice from the Master10 academic board
Public Key Infrastructure provides the operational foundation for secure governance in competitive examinations. Candidates must distinguish between asymmetric encryption used for key exchange and high-speed symmetric ciphers used for bulk data payload encryption. Grasping the hierarchical delegation from root authorities to intermediate entities explains how digital identity remains verifiable without exposing root private keys. Statutory questions frequently test Section 35 of the Information Technology Act alongside CCA regulatory powers.
Technical evaluations examine certificate revocation mechanisms, contrasting bulky static Certificate Revocation Lists with low-latency Online Certificate Status Protocol checks. Aspirants should track how OCSP stapling prevents client privacy leaks while offloading validation burdens from certificate issuers. Moreover, understanding browser trust warnings solidifies practical knowledge. Remembering the core structural components ensures full marks on networking questions: memorize the CHAIN mnemonic: Certificate format, Hardware modules, Authority hierarchy, Identity verification, and Non-repudiation.
Related Knowledge Topics to Discover
Looking for more GK practice?
Explore 52,789+ questions across 65 General Knowledge categories.