%% You should probably cite draft-dekater-scion-pki-05 instead of this revision. @techreport{dekater-scion-pki-00, number = {draft-dekater-scion-pki-00}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-dekater-scion-pki/00/}, author = {Corine de Kater and Nicola Rustignoli}, title = {{SCION Control-Plane PKI}}, pagetotal = 64, year = 2022, month = aug, day = 26, abstract = {This document presents the trust concept and design of the SCION \_control-plane PKI\_, SCION's public key infrastructure model. SCION (Scalability, Control, and Isolation On Next-generation networks) is a path-aware, inter-domain network architecture. The control-plane PKI, or short CP-PKI, handles cryptographic material and lays the foundation for the authentication procedures in SCION. It is used by SCION's control plane to authenticate and verify path information, and builds the basis for SCION's special trust model based on so- called Isolation Domains. The document first describes the trust model behind SCION's control- plane PKI, and provides a short overview of the certificates, keys, and roles involved. It then continues with detailed specifications of the building blocks of SCION's control-plane PKI. The document concludes with several considerations in regard to deploying the control-plane PKI.}, }