CARAT: A Guide to the Development of
Electronic Commerce Relationships
Background
A number of states have adopted laws and regulations to govern electronic commerce. The nature of electronic commerce, however, requires some consistency across state boundaries to ensure that rules and regulations do not present undue impediments to its development. To explore a perspective which goes beyond an individual state or region, the three national organizations which are the NECC founding partners retained the Internet Council of the National Automated Clearinghouse Association (NACHA) to facilitate this exploration. These groups partnered with NACHA and its private sector participants to develop a market-based means to evaluate and rate the trustworthiness and performance of certificate authorities issuing digital certificates as part of a Public Key Infrastructure (PKI)-based electronic commerce solution.
CARAT
The Certification Authority Rating and Trust (CARAT) Task Force developed guidelines intended to help organizations analyze their needs and build PKI to meet them. Consistent with NACHA's mission to facilitate electronic commerce across state boundaries, the CARAT guidelines are intended to help develop systems which are closed (limited to known parties with contractual relationships) but still interoperable.
The guidelines are intended to help organizations, called Policy Authorities, create PKIs that are then used to facilitate pilots and projects employing public key technology. A Policy Authority can use the guidelines to analyze its particular needs and construct PKI accordingly. An important product of that analysis is likely to be a Certificate Policy, which the guidelines suggest thinking of as a charter for a particular PKI. The Certificate Policy defines the parties, the uses that are acceptable within the PKI, and the relationships and obligations of the parties to each other.
Why Security?
Governments, businesses and other organizations which rely on electronic communication must be able to verify that messages and data have not been altered and that another party is not masquerading as the message originator. Electronic commerce security is designed to ensure these key components of trust - purity of data and identity - are guaranteed. This security may be supported by the use of digital signatures - technology which conveys the identity of the message sender and verifies the purity of the content or data.
Digital signatures are complex mathematical equations, sometimes embedded in software or carried on tokens, which are assigned to an individual or organization; they have two primary components. One of these components, the private key, is used to encrypt the message. The other component, the public key, allows the message receiver to decrypt the message and verify both who sent it and that it was not altered in transmission.
While two entities can interact using digital signatures alone, there should be some means of assuring that the parties are indeed who they say they are. A certificate authority or some other entity, such as the policy authority cited above, can act as a trusted third party with responsibility for verifying the identity of those with digital signatures.
The Guidelines
The CARAT guidelines are designed to help organizations analyze their business needs and build public key infrastructures to support these functions. The guidelines support the definition of parties to the development of these systems, the definition of the relationships among these parties, and the obligations of those involved.
The guidelines are published in a document "Guidelines for Constructing Policies Governing the Use of Identity Based Public Key Certificates" is available on the Internet Councils web site at http://internetcouncil.nacha.org/CARAT/ . The document is open for public comment. The Internet Council encourages interested parties to use the PKI guidelines to draft Certificate Policies and to provide feedback about their experiences.