Re: Outreach via wikipedia articles on authentication and authorization
"Karp, Alan H" <[email protected]>
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <8AD823089998C849A832D86972E69CD53E6BAC64@G4W3222.americas.hpqcorp.net> |
Rob Meijer wrote: > transferring accountability with delegation without actually unduly > delegating knowledge about identity, that IMO would be absolutely amazing. > Does this make sense? I think it does indeed make sense, and I believe you can do it with Horton. Each user is identified by an object that encapsulates a Be and a Who. The Be is an sealer-unsealer equivalent of a private key; a Who, that of a public key. The Horton paper assumed that the Who allowed anyone with a reference to it to be able to determine who (pun intended) it was for. There is nothing to say that there can't be a facet of the Who object that can obscure that identity information. ________________________ Alan Karp Principal Scientist Enterprise Services, Office of the CTO Hewlett-Packard Company 1501 Page Mill Road Palo Alto, CA 94304 (650) 857-3967, fax (650) 857-7029 http://www.hpl.hp.com/personal/Alan_Karp