Guidance
Design and build a privately hosted Public Key Infrastructure
Principles for the design and build of in-house Public Key Infrastructure (PKI)
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
Page 1 of 21

A private Public Key Infrastructure (PKI) is used to confirm the identity of users, devices and services hosted or connected to privately owned infrastructure.
This is an essential component of any system that uses a private PKI for authentication, as such it must be designed and built with great care.
This guidance provides a set of high level architectural design principles which can be used to design, scope or review a private PKI architecture.
Please note this guidance is not intended to provide advice for PKI's that exist on the public Internet that form part of the public root of trust.
These principles are intended as high level guidance for architects, designers and engineers.
The guidance consists of 12 design principles, which will help guide your thinking as you develop an in-house (private) PKI.
These principles are prefaced by a discussion of what a PKI is and how it works.
The algorithms used to sign data in PKI systems are not resistant to attack by a Quantum computer. Therefore, there will be a requirement to change algorithms in the future to primitives that are resistant to an attack from a Quantum computer.
NIST and ETSI are currently investigating future quantum resistant algorithms. In the future there will be a need to change the algorithms used with quantum resistant algorithms. This will involve an upgrade to the various systems involved with in the PKI (CA, Hardware backed storage etc).
There will be a period of time where these two types of algorithms will run in parallel before there is a switch in algorithms. We expect the principles to be the same but there will be a change in algorithm.
Until NIST and ETSI have delivered a standardised list it will be difficult to advise further. The NCSC have published a white paper on this subject which is a good source for further reading.


