<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.dekater-scion-pki" target="https://datatracker.ietf.org/doc/html/draft-dekater-scion-pki-02">
   <front>
      <title>SCION Control-Plane PKI</title>
      <author initials="C." surname="de Kater" fullname="Corine de Kater">
         <organization>SCION Association</organization>
      </author>
      <author initials="N." surname="Rustignoli" fullname="Nicola Rustignoli">
         <organization>SCION Association</organization>
      </author>
      <date month="February" day="28" year="2023" />
      <abstract>
	 <t>   This document presents the trust concept and design of the SCION
   _control-plane Public Key Infrastructure (PKI)_, SCION&#x27;s public key
   infrastructure model.  SCION (Scalability, Control, and Isolation On
   Next-generation networks) is a path-aware, inter-domain network
   architecture.  The control-plane PKI, or short CP-PKI, handles
   cryptographic material and lays the foundation for the authentication
   procedures in SCION.  It is used by SCION&#x27;s control plane to
   authenticate and verify path information, and builds the basis for
   SCION&#x27;s special trust model based on so-called Isolation Domains.

   This document first introduces the trust model behind the SCION&#x27;s
   control-plane PKI, as well as clarifications to the concepts used in
   it.  This is followed by specifications of the different types of
   certificates and the Trust Root Configuration.  The document then
   specifies how to deploy the whole infrastructure.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-dekater-scion-pki-02" />
   
</reference>
