In cryptography, a web of trust is a concept used in PGP, GnuPG, and other OpenPGP-compatible systems to establish the authenticity of the binding between a public key and its owner. Its decentralized trust model is an alternative to the centralized trust model of a public key infrastructure (PKI), which relies exclusively on a certificate authority (or a hierarchy of such). As with computer networks, there are many independent webs of trust, and any user (through their identity certificate) can be a part of, and a link between, multiple webs.
The web of trust concept was first put forth by PGP creator Phil Zimmermann in 1992 in the manual for PGP version 2.0:
As time goes on, you will accumulate keys from other people that you may want to designate as trusted introducers. Everyone else will each choose their own trusted introducers. And everyone will gradually accumulate and distribute with their key a collection of certifying signatures from other people, with the expectation that anyone receiving it will trust at least one or two of the signatures. This will cause the emergence of a decentralized fault-tolerant web of confidence for all public keys.
Read more about Web Of Trust: Operation of A Web of Trust, Contrast With Typical PKI, Web of Trust Problems, Doing The Math, Mean Shortest Distance
Famous quotes containing the words web of, web and/or trust:
“The web of our life is of a mingled yarn, good and ill
together.”
—William Shakespeare (15641616)
“The web of our life is of a mingled yarn, good and ill
together.”
—William Shakespeare (15641616)
“Albany. Well, you may fear too far.
Goneril. Safer than trust too far.”
—William Shakespeare (15641616)