What is PKI? It is a public key infrastructure that helps businesses authenticate identities, protect data, and establish a secure digital communication environment through digital certificates and cryptographic key pairs. PKI is widely used in HTTPS, digital signatures, user authentication, email security, VPNs, and many enterprise systems. In this article, TOT provides a comprehensive explanation of what PKI is, its core components, how it works, and the most common PKI models.
>>> Read more:
- What is website security? Its importance and how to keep your website safe
- Causes of and fixes for security errors when accessing a website
- What is pentest? Essential things to know about penetration testing
- What is AES? The data encryption standard and the operating modes of AES
- Build an app for Android/iOS easily, no coding required
What is PKI?
PKI (Public Key Infrastructure), or public key infrastructure, is a system that combines security technologies and processes to allow parties to communicate securely with one another in the digital environment, through digital certificates and asymmetric encryption key pairs (comprising a public key and a private key). It is the foundation for authenticating identities, encrypting data, and protecting information from unauthorized access.
A PKI system includes components such as hardware, software, policies, and processes, along with Certificate Authorities (CAs), which are responsible for verifying identities and issuing certificates. Such a system is commonly deployed in communications over the Internet, for example between a browser and a server, or between systems within a business.
Technically, PKI works based on the principle of public key cryptography, which allows users to share the public key widely while keeping the private key secret. This mechanism ensures integrity, authentication, and security in digital activities such as electronic signing, information transmission, and system access.
>>> Read more:
- What is CSRF? Attack techniques and how to prevent CSRF effectively
- A detailed guide to the best way to secure a WordPress website
- Common website security certificates
- Reputable, professional, premium website design services in Da Nang
- Premium, SEO-optimized custom website design services

The role and functions of PKI
PKI (Public Key Infrastructure) plays the role of building a digital trust foundation for identity authentication, data protection, and cryptographic key management. Rather than merely providing an encryption mechanism, PKI public key infrastructure covers the entire lifecycle of keys and digital certificates, from key generation, certificate issuance, and authentication to distribution and revocation. As a result, PKI can be deployed at scale for users, servers, devices, applications, and IoT systems.
The role of PKI in information security
The core role of PKI is reflected in four aspects:
- Identity authentication: PKI helps verify whether a user, server, device, or organization is truly the registered subject. The certificate serves to bind an identity to its corresponding public key.
- Data security: PKI supports secure encryption and key exchange mechanisms, reducing the risk of data being read without authorization during transmission.
- Ensuring integrity: When data is signed with a private key, the recipient can use the public key to verify the signature and detect whether the content has been altered.
- Supporting non-repudiation: A digital signature can provide evidence of the origin and the signing action of a subject. However, the value of non-repudiation also depends on the technical mechanism, the authentication process, and the legal requirements of each system.
Cryptographic key management function
One of the important functions of PKI infrastructure is managing the lifecycle of the public and private key pair. The process may include generating keys, distributing the public key, protecting the private key, binding the public key to an identity through a certificate, and renewing, replacing, or revoking keys when necessary.
It is worth noting that PKI is not simply a key generation mechanism. It is a system for managing keys and identities at scale, helping businesses control keys and certificates consistently throughout their entire lifecycle of use.
Digital certificate issuance and management function
PKI provides a certificate management process from the moment a request is raised until the certificate is no longer valid. The main activities include receiving certificate requests, verifying subject information, issuing the certificate, renewing, updating or replacing it, and revoking the certificate when needed.
In this process, the CA (Certificate Authority) is responsible for issuing and signing certificates, while the RA (Registration Authority) may handle receiving and verifying subject information, depending on the deployment model.
Authentication and trust chain building function
PKI uses a trust chain to determine whether a certificate can be trusted. In the common model, the chain takes the form:
Root CA → Intermediate CA → Certificate → User/Server/Device
When validating a certificate, the system checks not only the CA’s signature but also several conditions: whether the certificate was issued by a trusted CA, whether it is still valid, whether it has been revoked, and whether the entire certificate chain is valid. This mechanism helps build structured trust between subjects in the digital environment.
Certificate revocation and status checking function
A certificate may need to be revoked before its expiration if the private key is compromised, the certificate was issued with incorrect information, or the subject is no longer eligible to use it. PKI supports certificate status checking through two common mechanisms:
- CRL (Certificate Revocation List): a list of certificates that have been revoked by the CA.
- OCSP (Online Certificate Status Protocol): a protocol that lets a system query the status of a single certificate instead of having to download and check the entire CRL.
As a result, the system can avoid continuing to trust a certificate that is no longer secure or valid.
Support function for digital signatures and encryption
PKI supports two important cryptographic purposes: digital signatures and encryption. With digital signatures, the subject uses the private key to sign data, and the recipient then uses the corresponding public key to verify the signature:
Private Key → Sign data → Digital Signature
Public Key → Verify the Digital Signature
For encryption, the public key can be used in encryption mechanisms or to establish a secure session key, depending on the specific protocol and algorithm. The key value of PKI lies in providing a trust mechanism to determine which subject a public key actually belongs to, rather than simply using a public key with no identity information.
Digital identity management function
The scope of PKI is not limited to websites and HTTPS. This infrastructure can manage many types of digital identity, including the identities of users, servers, devices, applications, and IoT devices. Each identity can be tied to an appropriate certificate and cryptographic key to serve authentication or secure communication.
For businesses with thousands of users and devices, this approach helps shift from manual identity management to centralized management with clear policies and lifecycle control.
>>> Read more:
- What is WCAG? How to improve the accessibility of your website
- What is vulnerability assessment? A solution for scanning and managing security vulnerabilities
- The cost of app design and maintaining an app on CH Play and the App Store
- Online sales website design to boost rankings and increase revenue
The components of PKI
PKI is a system made up of multiple components that work together to manage digital identities, cryptographic keys, and digital certificates throughout their lifecycle of use. Each component has its own role, from verifying identities and issuing certificates to storing, checking the status of, and revoking certificates. In addition to technology, PKI also needs clear operating policies and processes to ensure that certificates are issued and used for the right purposes.
CA (Certificate Authority) – The certification authority
A CA (Certificate Authority) is the authority responsible for issuing, signing, and managing digital certificates in a PKI system. The CA confirms the binding between a subject’s identity and the public key recorded in the certificate. When a certificate is issued, the CA uses its own private key to create a digital signature on the certificate. The recipient can use the CA’s public key to verify this signature.
A CA can issue certificates to many different subjects, such as users, servers, devices, or applications. In a hierarchical PKI system, CAs are typically organized into a Root CA and Intermediate CAs:
- Root CA: Located at the top of the trust hierarchy, it holds the critically important root key. The Root CA is usually stored offline in a high-security environment to defend against cyberattacks.
- Intermediate CA: Authorized by the Root CA to directly sign and issue certificates to end users. This model helps minimize the risk of exposing the Root CA’s key if an intermediate CA is compromised.
This separation helps reduce the risk to the Root CA and allows businesses to organize their certificate issuance system across multiple levels.
RA (Registration Authority) – The registration and identity verification authority
An RA (Registration Authority) is the component that performs or supports the process of receiving and verifying identities before the CA issues a certificate. The RA can check the information of users, businesses, servers, or devices based on the verification requirements defined in the PKI policy.
For example, when an employee requests a certificate to authenticate within an internal system, the RA can check the employee’s account details and permissions before forwarding the request to the CA. Only after the verification process is complete does the CA proceed to issue the certificate according to the established policy.
The RA and CA can be deployed as separate systems or integrated within the same platform, depending on the scale and architecture of the PKI. Separating identity verification from certificate issuance gives the identity management process an additional layer of control.
Digital Certificate
A Digital Certificate is an electronic data structure used to bind a public key to the identity of a subject. In Internet PKI, certificates are commonly based on the X.509 standard and are signed by a CA so that other parties can verify their authenticity.
A certificate can contain a range of information, such as:
- Subject: Identifying information about the owner (personal name, domain name, organization).
- Public Key: The owner’s public key.
- Issuer: Information about the issuing CA.
- Validity Period: The period of validity (start date and expiration date).
- Serial Number: The unique identifier of the certificate.
- Digital Signature: The digital signature created by the CA to prevent forgery.
A certificate is therefore not a public key. The public key is a component inside the certificate, while the certificate adds identifying information and the CA’s signature to create the basis for establishing trust.
Public Key & Private Key – The public and private key pair
The Public Key and Private Key are a key pair belonging to a public key cryptography system. The two keys are mathematically related but are used for different purposes depending on the algorithm and protocol.
- Public Key: Can be shared with other parties. The public key is used to verify a digital signature created by the corresponding private key, or to participate in encryption and key establishment mechanisms depending on the algorithm and protocol.
- Private Key: Must be strictly protected and used only by the subject that owns it. The private key can be used to create digital signatures or to participate in decryption/key establishment within appropriate cryptographic mechanisms.
In PKI, the digital certificate binds the public key to the identity of a user, server, or device. Thanks to this, the recipient can determine that the public key belongs to the correct subject. Protecting the private key is a critical requirement because if it is exposed, an attacker could impersonate the subject in activities that rely on the key.
Certificate Repository – Certificate storage and distribution
A Certificate Repository is where certificates, CRLs, and related information are stored and made available so that other systems can retrieve them when needed. A repository can be implemented in various forms, such as a directory service, a dedicated server, or a centralized certificate management system.
When a client needs to validate the certificate of a server or user, the system may need to retrieve the certificate of an intermediate CA, the Root CA, or related revocation information. A repository makes the distribution of this data more consistent and convenient.
In enterprise environments with a large number of certificates, organizing the repository effectively is especially important. If certificates are scattered, hard to find, or not updated in time, the certificate validation and lifecycle management processes may generate errors.
CRL/OCSP – Certificate checking and revocation mechanisms
Certificates have a validity period, but in some cases they need to be revoked before expiration. For example, a server’s private key is exposed, a certificate is issued with incorrect information, or the subject is no longer permitted to use the certificate.
The two common mechanisms for checking the status of a certificate are CRL and OCSP.
- CRL (Certificate Revocation List) is a list of certificates that have been revoked by the CA. The system can download the CRL from a published address and check the serial number of the certificate being validated.
- OCSP (Online Certificate Status Protocol) works by querying the status of a single certificate through an OCSP responder. Instead of having to download the entire revocation list, the client can send a request to receive the corresponding status information.
CRL and OCSP serve the same goal of helping a system stop trusting a revoked certificate, but the two mechanisms differ in how they operate and in their deployment requirements.
PKI policies & processes (CP/CPS) – Defining how PKI is operated
A PKI system cannot operate effectively based on the CA, certificates, and cryptographic keys alone. Businesses also need policies and processes that define who certificates are issued to, in which cases they are used, how identities are verified, and how to respond when a certificate or private key encounters an issue.
Two commonly encountered concepts are CP (Certificate Policy) and CPS (Certification Practice Statement).
- Certificate Policy (CP) defines the rules and requirements related to the use of certificates. The policy can specify who is eligible to be issued a certificate, the level of identity verification, the intended purpose of use, and the key protection requirements.
- Certification Practice Statement (CPS) describes how the organization implements those policies in practice. Its content can include the processes for receiving requests, verifying identities, issuing certificates, managing keys, renewing, and revoking.
Therefore, a trustworthy PKI system needs to combine both technology and process. The CA handles certification, the RA supports identity verification, the certificate binds an identity to a public key, the repository supports distribution, CRL/OCSP checks status, and CP/CPS set out the principles so that the entire system operates consistently and securely.
>>> Read more:
- What is application software? Examples, functions & commonly used software
- Professional, good-value custom software design in Hanoi
- Custom software development in HCMC, professional design across diverse platforms
- SEO-standard website design services, professional and conversion-optimized

How PKI works
PKI works based on the combination of a cryptographic key pair, digital certificates, a certificate authority, and mechanisms for authentication and status checking. The process begins with generating a public key and a private key, after which the public key is bound to an identity through a certificate issued by the CA. When the certificate is used, the system can check its validity before allowing authentication, establishing a secure connection, or verifying a digital signature.
The entire process can be visualized through six main steps:
1. Generating the key pair
A user, server, device, or application first generates a cryptographic key pair, consisting of a public key and a private key. The two keys are mathematically related and are used for different purposes depending on the algorithm and protocol.
The public key can be shared with other parties. Conversely, the private key must be strictly protected and used only by the subject that owns it. If the private key is stolen or exposed, an attacker could impersonate the subject in systems that rely on that key.
In an enterprise environment, the private key can be protected by mechanisms such as security hardware or a key management system to reduce the risk of unauthorized access.
2. Issuing the digital certificate
After obtaining the key pair, the subject submits a request for a digital certificate. The request typically contains the public key along with the identifying information that needs to be certified.
The CA or the RA component carries out the identity verification process according to the system’s policy. If the request meets the necessary conditions, the CA issues the certificate and uses the CA’s private key to sign it.
At this point, the certificate creates a verifiable binding between the subject’s identity and the public key. This is a crucial factor that lets other parties know who, or which system, the public key in use belongs to.
3. Validating the certificate
When a party wants to establish a connection or authenticate a subject, the system checks the certificate that is provided. This process is not simply a matter of seeing whether the certificate is still valid.
The system can check the CA’s signature, the validity period, the intended purpose of use, the subject’s name or identity, the certificate chain, and the revocation status. For a certificate belonging to an intermediate CA, the system can also build and check the trust chain from that certificate up to a trusted Root CA.
If all the validation conditions are valid, the public key in the certificate can be trusted to continue the authentication process or to establish secure communication.
4. Encrypting and exchanging data
After the certificate has been validated, the public key can be used in cryptographic mechanisms to protect the data exchange process. In modern protocols such as TLS, the certificate mainly helps authenticate the server’s identity and provides the public key to help establish a session key.
The session key is typically used to encrypt data during communication because it is better suited to transmitting large amounts of data. As a result, the system combines the strengths of public key cryptography in establishing trust and exchanging keys with the performance of symmetric cryptography when transmitting data.
The corresponding private key plays an important role in authentication or key establishment, depending on the algorithm and protocol used.
5. Creating and verifying digital signatures
PKI also supports digital signatures, which allow the origin and integrity of data to be verified.
When a document or message needs to be signed, the subject uses the private key to create a digital signature. The recipient uses the corresponding public key to verify the signature. If the signature is valid, the recipient can determine that the data has not been altered since it was signed and that the signature was created with the corresponding private key.
However, the public key only reveals which private key the signature corresponds to. To determine which subject that public key belongs to, the system relies on the certificate and the trust chain provided by PKI.
6. Revoking the certificate when needed
A certificate is not always used up to its full expiration. If the private key is exposed, the certificate was issued with incorrect information, or the subject is no longer permitted to use the certificate, the CA can revoke it before the expiration date.
The revocation status can be distributed and checked through mechanisms such as CRL or OCSP. When the system detects that a certificate has been revoked, that certificate should no longer be treated as a basis of trust for authentication activities.
Thus, PKI is not just the process of generating keys and issuing certificates. It is a cycle of managing identities and cryptographic keys throughout their lifecycle, from generating the key pair, verifying identities, and issuing and using certificates to checking, renewing, and revoking them when necessary. It is precisely this process that makes PKI the foundation for HTTPS, digital signatures, user and device authentication, and many other security applications.
>>> Read more:
- What is an offshore development center? An optimal solution for businesses
- What is DNS over HTTPS? Understanding how DoH works
- What is RFI? The role of the request for information in business
- Professional, all-inclusive, detailed website design quotes

Common PKI models
Depending on the size of the organization, security requirements, and the way trust relationships are built, PKI can be deployed using several different models. Each model differs in how it establishes trust, its scalability, and its level of administration.
Summary table of common PKI models:
| PKI model | How trust is built | Main advantages | Limitations |
| Hierarchical PKI | Root CA → Intermediate CA → End Entity | Easy to manage, scales well | The Root CA is a critical point of trust |
| Mesh / Cross-Certification | CAs cross-certify one another | Connects multiple independent PKIs | Trust management becomes complex at scale |
| Bridge CA | A Bridge CA connects multiple CAs/PKIs | Suitable for connecting multiple organizations | Requires tight administration of trust relationships |
| Single CA | A single CA issues certificates directly | Simple, easy to deploy | Limited scalability and delegation |
| Web of Trust (WoT) | Users directly certify one another | No dependence on a central CA | Hard to manage in large environments |
| Hybrid PKI | Combines multiple models | Flexible for each need | More complex architecture and operations |
| DPKI | Decentralized identity/trust | Reduces dependence on a centralized CA | The technology and standards are still developing |
| Strict Hierarchical PKI | Trust follows a fixed hierarchical tree | Tight, clear control | Less flexible when the architecture changes |
Hierarchical PKI model
Hierarchical PKI organizes the system in a tree structure, with the Root CA at the highest level. Below the Root CA there can be one or more Intermediate CAs, responsible for issuing certificates to systems or entities at lower levels. The trust chain is built from the End Entity’s certificate up to the Intermediate CA and finally to the Root CA. This is a common model in PKI systems that need to organize CAs across multiple levels.
Mesh / Cross-Certification Model
Mesh PKI builds trust relationships between CAs through a cross-certification mechanism. One CA can issue a certificate for the public key of another CA, thereby establishing a trust relationship between independent PKI domains. Unlike the hierarchical model, the CAs in a mesh do not necessarily sit under the same Root CA. This model often appears when multiple organizations or PKI systems need to authenticate one another.
Bridge PKI model (Bridge CA)
Bridge PKI uses a Bridge CA as a link between independent PKI systems. Instead of requiring each CA to establish direct cross-certification relationships with all other CAs, PKI domains can connect through the Bridge CA. Each organization can still maintain its own CA, policies, and administrative mechanisms within its system. The Bridge CA mainly serves to connect trust domains rather than directly issuing certificates to every End Entity.
Single CA Model
The Single CA Model uses a single CA to issue and manage certificates across the entire system. The CA can directly issue certificates to users, servers, devices, or applications without deploying multiple CA tiers. Because there is only one CA, the trust structure is relatively simple and easy to visualize. This model is typically applied in systems with a relatively small management scope or those that require a simple PKI architecture.
Web of Trust (WoT) PKI model
Web of Trust (WoT) builds trust based on individuals or entities verifying and signing one another’s public keys. Instead of relying on a central CA, each participant can make an assessment of the trust level of the keys they have verified. These certification relationships form a web of trust among participants. The Web of Trust model is well known in systems that use OpenPGP.
Hybrid PKI Model
Hybrid PKI combines two or more PKI models or trust mechanisms within the same architecture. For example, a business can use Hierarchical PKI to manage internal certificates while also using cross-certification to connect with another PKI system. Different domains within the same organization can apply their own certificate management mechanisms yet still establish trust when needed. As a result, Hybrid PKI is often used for environments with complex architectures or a variety of security requirements.
Decentralized PKI (DPKI) model
Decentralized PKI (DPKI) aims to manage identities and trust relationships using a decentralized architecture, rather than depending entirely on a central CA. In some designs, information related to identity or public keys can be stored and verified through a blockchain or distributed ledger. DPKI is often associated with the concept of Decentralized Identifiers (DIDs) and self-sovereign identity models. The specific implementation depends on the chosen architecture, standards, and technology.
Strict Hierarchical PKI model
Strict Hierarchical PKI is a form of hierarchical PKI in which trust relationships are defined strictly according to a tree structure. The Root CA sits at the top, the Intermediate CAs are organized into defined levels, and End Entities are located on the lower branches. A certificate is trusted only when a valid certification chain can be built up to a trusted Root CA. This model emphasizes clear control over the scope of trust and certification authority across CA levels.
>>> Read more:
- What is SOC? The benefits of a Security Operations Center (SOC)
- Top 9 easiest-to-use, high-quality free app design software tools
- Top 20 most reputable, highest-quality app design companies in Vietnam

How does PKI differ from SSL/TLS and digital certificates?
PKI, certificates, and SSL/TLS often appear together in security systems, especially when deploying HTTPS. However, these are three concepts that differ in nature and role. PKI is the infrastructure and framework for managing digital identities and cryptographic keys; a digital certificate is authentication data that binds an identity to a public key; and TLS is the security protocol used to establish a secure connection over a network.
Table distinguishing PKI, certificates, and SSL/TLS:
| Criteria | PKI | Digital certificate | SSL/TLS |
| Nature | A framework/infrastructure comprising technology, policies, and processes for managing keys, certificates, and trust | An electronic data structure used to bind a public key to an identity | A security protocol for network communication |
| Main role | Managing the key and certificate lifecycle, authenticating identities, and building trust | Providing identity information, the public key, and authentication evidence from the CA | Authentication, session key establishment, and protecting data over the network connection |
| Relationship | Provides the environment and processes for certificates to be issued, managed, and revoked | A component managed by PKI and used by protocols such as TLS | Can use PKI’s certificates and trust model to authenticate the communicating parties |
| Example | A system of CAs, RAs, repositories, policies, and certificate management processes | The certificate of a website, server, user, or device | HTTPS uses TLS to protect the browser–server connection |
What is PKI in relation to a certificate?
PKI is a framework/infrastructure comprising technology, processes, policies, and related components used to manage public keys, private keys, and digital certificates throughout their lifecycle. PKI is not a specific certificate, but rather the environment that enables certificates to be created, issued, verified, renewed, replaced, and revoked in a controlled manner.
In PKI, the CA (Certificate Authority) plays the role of issuing and signing certificates. A certificate contains the public key along with the subject’s identifying information and the CA’s digital signature, thereby creating the basis for another party to verify that the public key is bound to the correctly certified identity. It can therefore be understood simply as follows: PKI is the trust management system, while the certificate is one of the core components managed by PKI.
What is a certificate?
A certificate, or digital certificate, is an electronic data structure used to bind a public key to a specific subject such as a website, server, user, organization, or device. In the Internet environment, certificates based on the X.509 standard are widely used so that systems can verify the identity and public key of the entity they are communicating with.
A certificate typically contains information such as the subject’s identity, the public key, the validity period, information about the issuing CA, and the CA’s digital signature. A certificate is not a public key. The public key is a component inside the certificate, while the certificate provides additional information about the identity and authentication evidence from the CA.
What is SSL/TLS?
SSL/TLS is a group of network communication security protocols, designed to protect the data exchanged between parties over a network connection. SSL is the older generation of the protocol and is no longer used in modern deployments, while TLS is the successor protocol and is now widely used.
TLS provides mechanisms for authenticating the communicating party, establishing a session key, and protecting data during transmission. In HTTPS, TLS is used to protect the connection between the browser and the web server. The certificate is usually provided by the server during the TLS handshake to prove its identity and provide the related public key. After the certificate is validated and the session key establishment is complete, application data is protected by the encryption mechanism of the TLS connection.
The relationship between PKI – Certificate – TLS
These three components can be visualized as a chain:
PKI
↓
The CA issues the Certificate
↓
The Certificate contains the Public Key and identity information
↓
TLS uses the Certificate to authenticate and establish trust
↓
The HTTPS connection is protected
In practice, when a browser accesses an HTTPS website, it receives the certificate from the server during the TLS handshake. The browser checks whether the certificate is signed by a CA it trusts, whether the certificate is still valid, whether the domain name matches the information in the certificate, and, depending on the mechanism deployed, the certificate’s revocation status. If the necessary conditions are met, TLS proceeds to establish the security parameters for the communication session.
In short, PKI is the foundation for managing trust and digital identity, the certificate is the electronic evidence that binds an identity to a public key, and TLS is the protocol that uses these mechanisms to protect network communication. Therefore, when a website uses HTTPS, all three can be seen taking part in the security process while playing entirely different roles.
>>> Read more:
- What is Threat Intelligence? A new direction in the field of cybersecurity
- What is XSS? How to test for and prevent XSS attacks effectively
- What is RSA? How RSA encryption works and its use in digital signatures
- What is PCI DSS? Understanding the card industry security standard & its 12 mandatory requirements
Real-world applications of PKI
PKI is used in many systems that need to authenticate identities, protect data, and establish a trustworthy communication environment. From websites, email, and software to IoT devices and enterprise systems, PKI helps organizations control digital identities and use cryptographic mechanisms in a systematic way. Some common applications of PKI include:
Web browsing security (HTTPS/SSL/TLS)
PKI is an important foundation for authenticating websites when users access them over HTTPS. The web server uses a digital certificate to prove its identity to the browser, while TLS uses the certificate and cryptographic mechanisms to establish a protected connection. As a result, the data exchanged between the browser and the server is protected from being read or altered without authorization during transmission.
Digital signatures for documents and files (Digital Signatures)
PKI supports the deployment of digital signatures to authenticate the signer and ensure the integrity of electronic documents. The signer uses the private key to create the signature, while the recipient uses the corresponding public key to verify it. The certificate issued by the CA helps bind the public key to the identity of the person or organization, thereby creating the basis for verifying the origin of the signature.
Code Signing
During software development and distribution, a code signing certificate is used to sign applications, packages, or executable code. The signature allows users and systems to verify which publisher the software comes from and whether the content has been altered after signing. PKI therefore contributes to increasing trust when a business releases software, desktop applications, mobile apps, or other software components.
User and device authentication
PKI can be used to authenticate users, servers, computers, and devices instead of relying only on passwords. Certificates can be issued to individual users or devices to prove their identity when accessing internal systems, APIs, or protected resources. For enterprise environments with a large number of endpoints, this approach helps build an authentication mechanism based on digital identity and enforces tighter access control.
Virtual private networks (VPN) and enterprise Wi-Fi
PKI is often used in VPN and enterprise Wi-Fi systems to authenticate a device or user before allowing a connection. For example, certificates can be used in EAP-TLS-based authentication mechanisms for enterprise Wi-Fi networks. With VPNs, certificates can also support client or server authentication, helping reduce dependence on static credentials and increasing control over device identities.
Email security (S/MIME)
S/MIME uses certificates and public key cryptography to support signing and encrypting email. The digital signature helps the recipient verify the sender and detect altered content, while encryption helps protect the email content from unauthorized parties. PKI provides the mechanisms for issuing and managing the certificates needed for this process.
Internet of Things communication (IoT Security)
In an IoT system, each device can be issued its own digital identity and certificate to authenticate when connecting to a gateway, server, or cloud. PKI helps a device prove its identity without sharing a single set of authentication credentials across the entire system. Managing certificates by lifecycle also supports revoking the identity of a device that has been compromised or is no longer permitted to connect.
Security for banking transactions and e-commerce
PKI is used in many security layers of banking and e-commerce, especially in protecting HTTPS connections, authenticating systems, and supporting digital signatures. When a customer performs an online transaction, TLS helps protect the transmission channel, while PKI-based mechanisms can be used to authenticate the server, user, device, or transaction depending on the system’s architecture.
Security for e-government systems
E-government platforms can use PKI to manage the digital identities of officials, organizations, businesses, and public service systems. PKI-based digital signatures support signing documents, records, and electronic transactions, while certificates can be used to authenticate systems and devices. As a result, PKI helps build a digital transaction environment capable of authentication, ensuring integrity and clear identity control.
>>> Read more:
- What is Brute Force? Its causes and how to prevent it effectively
- What is a security vulnerability? Understanding website vulnerabilities and how to prevent them effectively
- What is OWASP? The top 10 vulnerabilities and security risks according to OWASP

The benefits of PKI for businesses
For businesses, PKI serves not only to encrypt data but also to create a foundation for managing digital identities, authenticating, and controlling communication activities across the entire system. As the number of users, servers, devices, and applications continues to grow, PKI helps businesses build a structured trust mechanism, rather than managing each account, key, or certificate separately.
Strengthening identity authentication
PKI allows businesses to authenticate users, servers, and devices based on certificates and cryptographic key pairs. Instead of relying only on passwords, the system can require a device or user to prove ownership of the private key corresponding to a valid certificate. This approach helps reduce the risk from stolen credentials and increases trust when controlling access to internal resources.
Protecting data and communication
PKI supports the establishment of secure communication channels through protocols that use public key cryptography, such as TLS. Businesses can use certificates to authenticate servers, devices, or participating parties before establishing a connection. Combined with encryption and integrity-checking mechanisms, PKI helps protect data as it travels between users, applications, servers, APIs, and enterprise systems.
Supporting digital signatures
PKI provides the foundation for deploying digital signatures for documents, contracts, transactions, and software. The private key is used to create the signature, while the corresponding public key is used to verify the signature and the integrity of the content. When the public key is bound to an identity through a certificate, a business can determine the subject behind the signature and increase trust in electronic transaction processes.
Managing device identities
In an environment with thousands of computers, servers, mobile devices, or IoT devices, determining which device is allowed to connect becomes an important requirement. PKI allows a separate certificate to be issued for each device, creating a digital identity that can be used during authentication. When a device is lost, compromised, or no longer permitted to operate, the corresponding certificate can be revoked to prevent the device from continuing to be trusted.
Centralized certificate lifecycle management
PKI helps businesses manage certificates according to a unified lifecycle, from the request for issuance, verification, and issuance to renewal, replacement, and revocation. Centralizing the process helps prevent situations where a certificate expires without being detected, a certificate that is no longer suitable is still in use, or it is difficult to determine which system a certificate belongs to. In large environments, businesses can combine PKI with automation tools to reduce the volume of manual administrative work.
Increasing control and compliance
PKI creates consistent policies and processes for managing identities, keys, and certificates. Businesses can clearly define who or which devices are issued certificates, what purpose the certificates are used for, how long they are valid, and when they must be revoked. Centralized management, together with the ability to log certificate-related activities, also supports auditing, internal control, and meeting the security or compliance requirements relevant to each industry.
Overall, the greatest benefit of PKI for businesses is building a trust foundation that can be managed at scale. Instead of handling identities and cryptographic keys system by system, a business can standardize how it authenticates, protects communication, and manages certificates across its entire digital environment.
>>> Read more:
- What is Cyber Security? 9 common types of Cyber Security
- 40 accurate website security and malware scanning tools
- Top 35 most professional and reputable website design companies in Vietnam
- Professional, SEO-standard, results-optimized website design services

Security issues related to PKI
PKI helps businesses build authentication and trust mechanisms at scale, but the infrastructure itself can also become a target of attack. An incident involving a private key, a CA, a certificate, or the key management system can affect many users, devices, and services at the same time. Therefore, PKI security needs to be considered in terms of technology, configuration, and operational processes alike.
Exposure or theft of the private key
The private key is a component that must be strictly protected. If the private key of a user, server, or CA is exposed, an attacker can use the key to impersonate the corresponding subject or create unauthorized signatures. The risk is especially serious when a CA’s private key is compromised, because it can affect the trustworthiness of all the certificates issued by that CA.
Attacks on the Certificate Authority (CA)
The CA is one of the most important points of trust in a PKI. If a CA is compromised, an attacker may attempt to access the private key, change the configuration, or abuse the certificate issuance privilege. Therefore, a CA typically needs to be protected with strict access control, separation of privileges, and dedicated key protection measures.
Forged or wrongly issued digital certificates
A certificate can become a risk if it is issued for the wrong identity, the wrong domain name, or the wrong intended use. If a CA is abused or the identity verification process is not rigorous enough, an untrustworthy certificate can be introduced into the system. This weakens the trust model and can create conditions for impersonation attacks.
Expired or revoked digital certificates
Certificates have a validity period and can be revoked before expiration when the private key is exposed, the certificate information is no longer accurate, or the certificate is no longer permitted for use. If the system does not detect an expired certificate or does not check the revocation status properly, a service can be disrupted or can continue to trust a certificate that is no longer secure.
Man-in-the-Middle (MITM) attacks
PKI and certificates help parties authenticate identities in protocols such as TLS, thereby reducing the risk of connecting to a fake server. However, if a certificate is issued incorrectly, a CA is compromised, or the certificate validation system is misconfigured, an attacker can attempt to insert themselves in the middle of the communication process. This is why checking certificates and the trust chain must be done accurately.
Attacks on the key management system
Besides the CA, the systems that store and manage private keys are also high-value targets. An attacker may attempt to exploit vulnerabilities in the key management system, administrative credentials, or backup mechanisms to access keys. Controlling access, encrypting keys at rest, and protecting keys with dedicated hardware can help reduce the risk.
Denial-of-service attacks (DoS/DDoS)
PKI components such as the CA, the OCSP responder, or the repository can become targets of DoS/DDoS attacks. When the authentication or certificate status checking service is unavailable, some systems may have difficulty establishing connections or verifying identities.
Vulnerabilities in cryptographic algorithms and protocols
PKI depends on cryptographic algorithms and protocols to protect keys, certificates, and data. When an algorithm becomes weak or a protocol has a vulnerability, the security level of the system can decline. Businesses need to monitor the lifecycle of their algorithms, remove outdated cryptographic mechanisms, and update their configuration according to appropriate security standards.
Configuration errors and manual processes
Not every PKI incident stems from a direct attack. A wrongly issued certificate, incorrect trust configuration, forgetting to renew, or poorly controlled private key management can all create vulnerabilities. As the number of certificates and devices grows, relying too heavily on manual operations further increases the risk of errors and makes control more difficult.
The threat from quantum computing
Large-scale quantum computing in the future could affect some of the public key cryptographic algorithms currently used in PKI. In particular, systems based on RSA and elliptic-curve cryptography need to be considered in the plan to migrate to Post-Quantum Cryptography (PQC). Businesses with critical PKI systems should begin monitoring their migration capability and managing crypto-agility so they can replace algorithms when necessary.
In general, PKI is only secure when the entire trust chain, keys, certificates, management systems, and operational processes are all protected. Businesses should not focus only on the CA but need to manage the entire PKI lifecycle, from generating keys and issuing certificates to monitoring, renewing, revoking, and replacing them.
Conclusion
Understanding what PKI is helps businesses grasp how PKI supports the management of digital identities, cryptographic keys, and digital certificates in the digital environment. PKI is used in HTTPS, digital signatures, user and device authentication, email security, IoT, and electronic transactions. When deployed correctly, PKI helps strengthen authentication, protect data, and control the certificate lifecycle, while reducing security risks during operation.
Frequently asked questions
What is PKI?
PKI (Public Key Infrastructure) is a public key infrastructure used to manage cryptographic keys, digital certificates, and digital identities in the electronic environment. PKI helps authenticate users, servers, or devices while also supporting data encryption and digital signatures. Such a system typically includes CAs, RAs, digital certificates, public–private key pairs, and certificate lifecycle management mechanisms.
What components does a PKI system include?
A PKI system typically includes a Certificate Authority (CA), a Registration Authority (RA), digital certificates, public and private key pairs, a certificate repository, and status checking mechanisms such as CRL or OCSP. In addition, PKI also has a Certificate Policy (CP) and a Certification Practice Statement (CPS) to define the policies and how the system operates. Depending on the architecture, these components can be deployed centrally or separately.
What does “a product is a cryptographic component in a PKI system” mean?
“A product is a cryptographic component” is usually understood to mean a product or device that provides cryptographic functions for a PKI system, such as generating, storing, and using cryptographic keys or performing signing, authentication, and encryption. Examples include an HSM, smart card, USB token, or cryptographic software. This component helps protect the private key and perform cryptographic operations according to the PKI system’s security policy.
How is PKI applied in business?
In business, PKI is applied to secure websites and transactions over HTTPS, deploy digital signatures, authenticate users and devices, protect email with S/MIME, connect via VPN or enterprise Wi-Fi, and manage IoT device identities. PKI also helps businesses control the digital certificate lifecycle, from issuance and renewal to revocation, thereby increasing manageability and reducing security risks.
What is a PKI token?
A PKI token is a hardware device used to store and protect cryptographic keys, typically the private key, while also supporting operations such as digital signing or authentication. A USB token is a common example in digital signature systems. The private key can be used directly on the device without being exported to a computer, helping reduce the risk of it being copied or stolen during use.
What is a PKI key? What is a public key?
A PKI key is a cryptographic key used in a PKI system, typically comprising a pair of a public key and a private key. The public key can be shared and is usually contained in a digital certificate for authentication or to perform cryptographic mechanisms. The private key must be strictly protected and used only by the authorized subject. The two keys are mathematically related but perform different functions.
Which type of key does a PKI system certify the trustworthiness of among cryptographic methods?
A PKI system is used mainly to authenticate and establish trust for the public key in public key cryptographic methods. PKI binds the public key to the identity of an individual, organization, server, or device through a digital certificate issued by a CA. As a result, the recipient can verify that the public key in use truly belongs to the correctly certified subject.