Public Key Infrastructure, commonly called PKI, is a system of technologies, policies, procedures, and trusted organizations used to establish digital trust.
It helps people, businesses, governments, and computer systems determine whether a digital identity or electronic message can be trusted.
PKI is based mainly on public key cryptography, which uses a mathematically related pair of keys: a public key and a private key. The public key can be shared, while the private key must be protected by its owner. This arrangement supports encryption, authentication, and digital signatures.

A central component of PKI is the digital certificate. A certificate connects a public key with an identified person, organization, website, device, or system. Certificate Authorities (CAs) issue and manage these certificates according to defined policies.
In a typical PKI hierarchy, a trusted root certificate authority sits at the top. Intermediate authorities may operate below it, followed by certificates issued to end users, websites, applications, or devices. This creates a chain of trust that can be checked by a computer or application.
In India, the Controller of Certifying Authorities (CCA) oversees the country's licensed Certifying Authorities. The Root Certifying Authority of India (RCAI) forms the top of the national PKI trust hierarchy.
How PKI Works
PKI combines several components that work together to establish and maintain digital trust.
- Public and private keys: The public key can be distributed, while the private key is kept confidential.
- Digital certificates: Certificates associate public keys with verified identities or other information.
- Certificate Authorities: CAs issue, renew, suspend, and revoke certificates according to applicable policies.
- Root Certificate Authorities: Root CAs provide the highest level of trust within a particular hierarchy.
- Certificate Revocation Lists: CRLs identify certificates that should no longer be trusted.
- Online Certificate Status Protocol: OCSP can be used to check whether a certificate has been revoked.
- Registration and identity verification: These processes help establish the identity associated with a certificate.
For example, when a user connects to a website protected by TLS, the browser can examine the site's certificate and its certificate chain. If the chain leads to a trusted certificate authority and the relevant checks succeed, the browser can establish a trusted connection.
PKI therefore does more than simply encrypt information. It provides a framework for identity verification, authentication, integrity, and non-repudiation in appropriate applications.
Why PKI Matters Today
Digital systems increasingly communicate without people being physically present to verify one another. Online banking, government portals, corporate networks, cloud applications, software distribution, email, and connected devices all need mechanisms for establishing trust.
PKI addresses several important security challenges:
| Security requirement | How PKI contributes |
|---|---|
| Authentication | Helps verify the identity associated with a certificate |
| Confidentiality | Supports encryption using public-key cryptography |
| Integrity | Digital signatures can reveal unauthorized changes |
| Digital identity | Certificates can bind identities to cryptographic keys |
| Trust management | Certificate hierarchies establish relationships between trusted entities |
| Revocation | CRLs and OCSP help identify certificates that should no longer be trusted |
PKI is relevant to both organizations and individuals. Enterprises may use it for employee authentication, secure communications, device identity, application security, and internal certificates. Government systems can use digital signatures and certificates to support electronic transactions and public administration.
India's CCA states that the Information Technology Act, 2000 provides legal recognition to electronic records and digital signatures based on asymmetric cryptography and hash functions.
Recent Developments in PKI
PKI continues to evolve as digital security requirements become more demanding. Recent developments have focused on certificate interoperability, identity verification, cryptographic protection, certificate authority governance, and the security of root trust stores.
India's CCA published several updated PKI guidelines during 2025 and 2026. The CCA guideline listing records an updated X.509 Certificate Policy for India PKI on July 1, 2025, followed by updated Certification Practice Statement and CA licensing-related guidelines in September 2025.
On June 16, 2026, the CCA listed updated versions of its Interoperability Guidelines for Digital Signature Certificates and Identity Verification Guidelines. In June 2026, it also listed updated SSL certificate guidance, while its crypto-device security requirements were updated in August 2026.
Internationally, browser-based Web PKI also continues to change. Mozilla's Root Store Policy 3.1, effective July 1, 2026, introduced additional requirements around CA documentation, transparency, assurance, and operational controls. Mozilla also introduced a requirement concerning the age of root CA key material for new root inclusion requests.
These developments show that PKI is not a static technology. Certificate authorities, browsers, operating systems, and regulators periodically update requirements to address changing security risks.
Laws and Policies in India
The primary legal foundation for India's PKI framework is the Information Technology Act, 2000. The Act established the legal and administrative framework for electronic signatures and the regulation of Certifying Authorities.
The CCA licenses Certifying Authorities under the IT Act and supervises their activities. It also certifies the public keys of licensed CAs and establishes standards that CAs must follow.
The Information Technology (Certifying Authorities) Rules, 2000 provide additional requirements for the operation of Certifying Authorities. The CCA explains that a CA must be licensed before operating under the Indian PKI framework.
The Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 are also relevant to the broader digital-security environment, although they are not PKI-specific laws. The final DPDP Rules were notified in November 2025 and establish requirements concerning the processing and protection of digital personal data.
Organizations using PKI therefore need to consider both certificate-specific requirements and broader information-security, privacy, and data-protection obligations applicable to their activities.
Tools and Resources for PKI
Several technical and official resources can help users understand, implement, or inspect PKI technologies.
- Controller of Certifying Authorities: India's official source for information about licensed CAs, PKI policies, root certificates, certificate revocation information, and digital signatures.
- OpenSSL: A widely used cryptographic toolkit that includes functionality for working with X.509 certificates and certificate-chain verification.
- Mozilla Root Store Policy: Useful for understanding how publicly trusted root certificates are evaluated and maintained in Mozilla software.
- NIST PKI publications: Provide technical background on certificate authorities, certificate revocation, trust models, and X.509-based PKI.
- Certificate inspection tools: Modern browsers and operating systems can display certificate information, including issuer, validity period, subject, and certificate chain.
The CCA also publishes information about Digital Signature Certificates, eSign, time-stamping, and Certificate Revocation Lists through its official PKI framework.
Frequently Asked Questions
What is PKI in simple terms?
PKI is a framework for establishing digital trust. It uses cryptographic keys, digital certificates, trusted authorities, and related procedures to help verify identities, protect communications, and support digital signatures.
What is the difference between a public key and a private key?
A public key is designed to be shared, while a private key must remain confidential. Depending on the cryptographic operation, the two keys work together to support encryption, authentication, or digital signatures.
What does a Certificate Authority do?
A Certificate Authority verifies information according to its certificate policies and issues digital certificates. It also manages certificate status, including renewal and revocation, under the applicable rules.
Why are certificates revoked?
A certificate may need to be revoked if its private key is compromised, the certificate information is no longer reliable, or another condition defined by the CA's policy requires the certificate to stop being trusted.
Is PKI used only for websites?
No. PKI can support many applications, including website security, digital signatures, secure email, device authentication, software signing, enterprise identity systems, and government electronic transactions.
Conclusion
Public Key Infrastructure provides an important foundation for digital trust. By combining public-key cryptography, digital certificates, trusted authorities, certificate validation, and revocation mechanisms, PKI helps systems determine who or what they are communicating with and whether digital information can be trusted.
In India, PKI operates within a regulated framework overseen by the Controller of Certifying Authorities under the Information Technology Act, 2000. Recent updates in 2025 and 2026 demonstrate continued attention to certificate interoperability, identity verification, cryptographic security, and CA governance.