[Fwd: Re: Outreach via wikipedia articles on authentication and authorization]
"Rob Meijer" <rmeijer-qWit8jRvyhVmR6Xm/[email protected]>
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <[email protected]> |
Just forwarding as this message was obviously meant to go to the list: ---------------------------- Original Message ---------------------------- Subject: Re: [cap-talk] Outreach via wikipedia articles on authentication and authorization From: "Domenico Rotondi" <[email protected]> Date: Wed, August 7, 2013 10:59 To: "Rob Meijer" <rmeijer-qWit8jRvyhVmR6Xm/[email protected]> -------------------------------------------------------------------------- On 7 Aug 2013 at 9:42, Rob Meijer wrote: Hi all, my 2 cents. IMHO there is actually no authentication in the example (and, in general, in a capability system) but only a "proof of owneship". Indeed, even if you are authenticated when you enter the gym, this is not strictly related to your locker; anyone having the possibility to physically access the lockers room and having your PIN can actually use your locker. The "proof of ownership" in this case is the knowledge of the PIN and of the location of your locker, which is indipendent from being authenticated as the owner of that locker. So I agree that the authentication issue is marginal, and not strictly requested, in a capability system. So I can create a token for Mr Smith granting him the right to do X on resource Y and the resource manager has only to be able to check if the token is Ok, check the proof of onwership (which could be tied to Mr Smith knowing the secret key of a public key reported in the token) and that the reuqets is in line with the reuqested operation and resource. Ciao Domenico > On Wed, August 7, 2013 06:46, Karp, Alan H wrote: > > Rob Meijer wrote: > >> > >> When I go to the gym, their locker system provides me with a locker > >> number, > >> I can than create my own authorization token (pin) and can than store my > >> stuff > >> in that locker, ones I'm done I can use the authority implied by the > >> locker-number + pin to again gain access to the locker. No identity, > >> no authentication presupposed or otherwise. > >> > > My gym has the same kind of lockers. Clearly, you can lock your stuff in > > any unused locker, whether it was assigned to you or not. What's really > > happening is that you are authenticated when you enter the gym and given > > the authorization to use any unused locker with the understanding that you > > will use the one assigned to you. That's something%2