Re: Outreach via wikipedia articles on authentication and authorization
"Rob Meijer" <rmeijer-qWit8jRvyhVmR6Xm/[email protected]>
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <[email protected]> |
On Thu, August 8, 2013 17:06, Karp, Alan H wrote: > Rob Meijer wrote: > >> transferring accountability with delegation without actually unduly >> delegating knowledge about identity, that IMO would be absolutely >> amazing. >> Does this make sense? > > I think it does indeed make sense, and I believe you can do it with > Horton. Each user is identified by an object that encapsulates a Be and a > Who. The Be is an sealer-unsealer equivalent of a private key; a Who, > that of a public key. The Horton paper assumed that the Who allowed > anyone with a reference to it to be able to determine who (pun intended) > it was for. There is nothing to say that there can't be a facet of the > Who object that can obscure that identity information. So how would you go and fit this facet to the concept of the revocable-anonymity? Lets say we add (Incident Response) Irene to the Horton picture. We would probably start off with Both Alice and Carol having a reference to Irene. How now do we introduce facets to Horton in a way that: 1) Does not disclose Bobs identity to Carol in the process of introduction. 3) Does not disclose Bobs identity to Irene until Carol reports an incident 3) Does allow Carol to explicitly allow Irene to disclose Bobs identity in case of an incident. That is, Bob should remain anonymous to Carol, but Irene should be able to identify Bob when Carol reports an anonymously committed (by Bob) incident to her. Tnx, Rob