Journal of Theoretical and Applied Information Technology 15th January 2020. Vol.98. No 01 © 2005 – ongoing JATIT & LLS ISSN: 1992-8645 www.jatit.org E-ISSN: 1817-3195 TOWARDS CERTFICATELESS PUBLIC KEY INFRASTRUCTURE: A PRACTICAL ALTERNATIVE OF THE TRADITIONAL PKI 1EIHAB B.M. BASHIER, 2MOHAMMED A. HASSOUNA, 3TAOUFIK BEN JABEUR 1,3Dept of Mathematics, CAAS, Dhofar University, P.O. Box: 2509, Salalah, Oman 2Faculty of Computer Studies, National Ribat University, P.O. Box: 55, Khartoum, Sudan E-mail:
[email protected],
[email protected],
[email protected] ABSTRACT Although the maturity and efficiency of the traditional PKI in managing the public keys of the enterprise users, it still has two central and interrelated challenges or limitations when the number of users get large: Scalability and Key management. These two challenges are of great concern to the organization's information security officials, who are working to manage public key infrastructure, especially when the organization's growth rate becomes large. The most two significant alternatives for the traditional PKI are: Identity-based Cryptography and Certificateless Cryptography. The Identity-based Cryptography (IBC) provides an easy way to manage the public keys of its users, without need to any kind of certificate and its managing overhead, where the identity of a user is its public key. The private key is provided by a trusted Key Generation Centre (KGC) after an authentication process that the user must follow. IBC has many security features, and there are many schemes in the literature that are based on this new concept. It has one major problem: The Key escrow, where all the private keys of the users are generated centrally by the KGC.