Public key infrastructure (PKI)
Public key infrastructure (PKI) is the set of roles, policies, and systems used to manage digital certificates, usually built on asymmetric cryptography. It covers issuing certificates that bind a public key to an identity, distributing them, and revoking them once they’re no longer trustworthy.
The word "public" in the name mostly refers to the type of cryptographic key involved – a public key, as opposed to a private one – rather than to the infrastructure being open to the public at large. Because this is a common source of confusion, the more precise terms open PKI and closed PKI are sometimes used to distinguish infrastructure that anyone can rely on from infrastructure operated privately within an organization.
A PKI is typically anchored by one of two trust models: a certificate authority, a trusted third party that vouches for the binding between a key and an identity, or a web of trust, in which participants vouch for one another directly without a central authority.