Fireside Chat: PKI has carried digital trust through every tech advance—now comes the hardest one
好的,我现在需要帮用户总结一篇文章的内容,控制在100字以内,并且不需要特定的开头。首先,我得仔细阅读这篇文章,理解其主要内容和重点。 文章主要讨论了PKI(公钥基础设施)在数字信任中的作用,特别是在面对AI和量子计算带来的挑战时的情况。PKI在过去30年里一直支撑着电子商务、云和物联网的发展,但现在面临两个重大威胁:自主AI代理和量子计算机的出现。 接下来,作者提到安全社区正在采取行动应对这些挑战。他们提到了C2PA标准,用于内容认证,以及为AI代理颁发数字护照的概念,使用现有的PKI基础设施来管理这些代理的身份和权限。 此外,文章还指出目前企业在这方面的采用率还很低,只有不到5%的企业为他们的AI代理创建了可验证的身份。因此,PKI能否快速扩展以应对这些挑战是当前的关键问题。 现在,我需要将这些信息浓缩到100字以内。要确保涵盖PKI的重要性、面临的挑战、解决方案以及当前的进展情况。 可能的结构是:首先说明PKI的作用及其面临的双重威胁(AI和量子计算),然后提到安全社区的应对措施(C2PA和数字护照),最后指出当前进展缓慢的问题。 现在试着组织语言: “公钥基础设施(PKI)作为数字信任的核心,在面对自主AI代理和量子计算带来的双重威胁时面临严峻挑战。安全社区正通过C2PA标准和为AI颁发数字护照等措施应对。然而,目前企业采用率低,能否及时扩展成为关键。” 这样大约85字左右,符合要求。 </think> 公钥基础设施(PKI)作为数字信任的核心,在面对自主AI代理和量子计算带来的双重威胁时面临严峻挑战。安全社区正通过C2PA标准和为AI颁发数字护照等措施应对。然而,目前企业采用率低,能否及时扩展成为关键。 2026-4-20 15:37:22 Author: securityboulevard.com(查看原文) 阅读量:8 收藏

The post Fireside Chat: PKI has carried digital trust through every tech advance—now comes the hardest one appeared first on The Last Watchdog.

By Byron V. Acohido

Public key infrastructure — the authentication and encryption framework that has held digital commerce together through every chaotic leap forward in technology — is facing a double whammy.

Related: Achieveing AI security won’t be easy

Autonomous AI agents are flooding enterprise networks, most without verified identities or any meaningful governance. What’s more, quantum computers are just around the corner — and when they arrive, current encryption becomes obsolete overnight.

I sat down with DigiCert CEO Amit Sinha at RSAC 2026 to discuss this. The identity management and encryption communities are not sitting on their hands. Here is what I learned that you should know.

PKI has been the quiet backbone of digital trust for 30 years. E-commerce needed it to authenticate strangers. The cloud and IoT needed it to manage machine identities at scale.

Each time the technology shifted, PKI scaled to meet the load — under strain, imperfectly, but it held. The question now is whether it can be extended fast enough to handle two simultaneous disruptions: autonomous AI agents spreading like wildfire through enterprises and a quantum threat that will require replacing the underlying encryption math entirely.

Sinha’s framing at RSAC was direct. “We are in a once-in-30-year upgrade cycle,” he told me.

Encouragingly, the security community is already moving on two fronts. The first has to do with a problem that has been building since generative AI made synthetic media cheap and easy to produce. Fake videos, fabricated audio, and AI-generated images are flooding the internet and enabling fraud at scale.

The industry’s answer is C2PA — the Coalition for Content Provenance and Authenticity — an open standard that cryptographically signs content at the moment of creation, embedding a verifiable record of origin and any subsequent changes directly into the file.

A trusted certificate authority vouches for authenticity, and anyone downstream can verify it. The standard is gaining real traction. Samsung built C2PA signing into the native camera app of the Galaxy S25, the first mass-market smartphone to carry it. Cloudflare has implemented it across roughly 20 percent of the web. DigiCert is a certified certificate authority under the standard.

The second front has to do with companies racing to deploy autonomous AI agents — software that does not just answer questions but takes actions, executes transactions, manages systems, and interacts with other agents, all without waiting for a human to confirm each step.

These AI agents have no verified identity. They operate on borrowed credentials or API tokens, with no reliable way to establish who — or what — is actually acting, on whose authority, and with access to what. Sinha explained how PKI can be extended to solve this the same way it solved machine identity in the cloud era.

Every agent, he says, should carry a “digital passport” — a cryptographic credential, issued through the same certificate infrastructure that authenticates websites and software; this would establish the agent’s identity, define what it is authorized to access, and allow it to be revoked instantly if need be.

Think of it the way Sinha does: when you arrive at an airport, your passport gets you into the secure area; your boarding pass governs exactly where you go from there. The standards to do this already exist — SPIFFE and SPIRE, adapted from cloud workload security — and DigiCert is extending its platform to issue and manage these credentials for AI agents at enterprise scale.

“As agents move from answering your questions to taking actions on your behalf, you need governance, you need auditability, you need the ability to revoke all those privileges — much like you would with any human,” he said.

Adoption, however, is in the earliest innings. DigiCert CTO Jason Sabin told CSO Online late last year that fewer than 5 percent of enterprises deploying autonomous agents have created verifiable identities for them. Sinha described what AI has done to the security industry’s clock as “time dilation” — what used to be a year’s worth of change now happens in weeks.

PKI has carried the load through every prior shift. Whether it can be extended fast enough for this one is the defining near-term question. I’ll keep watch, and keep reporting.

Listen to the full podcast for Sinha’s complete breakdown.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.

(Editor’s note: I used Claude and ChatGPT to assist with research compilation, source discovery, and early draft structuring. All interviews, analysis, fact-checking, and final writing are my own. I remain responsible for every claim and conclusion.)

April 20th, 2026

*** This is a Security Bloggers Network syndicated blog from The Last Watchdog authored by bacohido. Read the original post at: https://www.lastwatchdog.com/fireside-chat-pki-has-carried-digital-trust-through-every-tech-advance-now-comes-the-hardest-one/


文章来源: https://securityboulevard.com/2026/04/fireside-chat-pki-has-carried-digital-trust-through-every-tech-advance-now-comes-the-hardest-one/
如有侵权请联系:admin#unsafe.sh