Analysis reveals how non-state actors cooperate for authentication in online environments, suggesting an effective governance model.
This paper provides a detailed analysis of how private actors cooperate to facilitate authentication and provide trust and security to the Web. The World Wide Web’s Public Key Infrastructure (WebPKI) is a global governance structure forged through collective action among industry actors. Drawing on collective action theory and institutional analysis, we show how this regime of non-state actors produces a public good—global authentication of website identities—in a way that enhances security, privacy, and trust for websites and their users. Stakeholder analysis demonstrates how the production of digital certificates and the utilization of certificates for authentication and encryption necessitate interdependencies among Certificate Authorities (CAs) and Browsers/Operating Systems. These relationships are institutionalized by the Certificate Authority/Browser (CA/B) Forum and other voluntary industry organizations. Since their founding, these institutions have developed through stages of formalization, specialization, and expansion of their scope, and have sought to address various security and efficiency challenges through new standards. We conclude by exploring some measures for evaluating the efficacy of this governance regime. Quantitative findings include assessments of CA market concentration, institutional membership and participation trends, stakeholder voting behavior, and the composition of Browser root stores.
No takes yet. Share an insight, caveat, or question.
Grindal et al. (2025) studied this question.
Synapse has enriched 2 closely related papers on similar clinical questions. Consider them for comparative context: