Re: Outreach via wikipedia articles on authentication and authorization
"Karp, Alan H" <[email protected]>
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <8AD823089998C849A832D86972E69CD53E6BEC5B@G4W3222.americas.hpqcorp.net> |
Rob Meijer wrote: > 2) Identity is not decomposable or attenuable, so the authority > to access the information, either for access control or accountability > is not really suitable to do POLA with. As a practical matter, identity is decomposable in an interesting way. Let's say that we have an agreement to work on a document that we wish to keep secret, but we don't fully trust each other not to leak it for personal gain. We write a contract specifying that whoever leaks any part of the document will pay the other a $100 penalty. For the sake of argument, let's say that we have a perfect mechanism for determining who leaked the document. After we sign the contract, I delegate read/write permission to you, you delegate read permission to Alice. Alice delegates read permission of Chapter 1 to Bob. Bob delegates read permission to the first paragraph to Carol. (I can keep going, but you get the drift.) The granularity gets arbitrarily fine. Each delegation and each access to the document records the identity of the person taking the action and the entire delegation chain to that point. Sounds horrible. There's no privacy at all. Identities are everywhere. I assume that's what you mean when you say that identity is not attenuatable. Now say that Carol leaks her paragraph, and I find out about it. What will I do? I will ask YOU for $100. The point is that I never heard of Carol, have no way to contact her, and even if I did, I have no contract with her to force her to pay. You, also, never heard of Carol, but you know from the recorded delegation chain that she got it from somebody named Bob that you never heard of. Fortunately for you, you know that Bob got it from Alice, whom you do know. You enforce your contract with Alice to get $100 from her. The process continues until we reach the end of the delegation chain or somebody doesn't demand payment from the next person. The point here is that a delegation carries rights and responsibilities, which is the definition of a contract. We need a mechanism to assign blame when the terms of the contract are violated even if it's only an implicit contract. That mechanism involves identity, but that identity need only be pairwise. I know you, you know Alice, etc. However, I get to choose what I call you, you get to choose what you call Alice, etc. When I find out that Carol leaked the paragraph, I tell you that your Alice's Bob's Carol is the culprit, but I have no way to use that information to identify Carol directly. It's up to you to handle the next link in the delegation chain. In this sense identity is attenuatable down to the granularity of the pairwise relationships. ________________________ Alan Karp Principal Scientist Enterprise Services, Office of the CTO Hewlett-Packard Company 1501 Page Mill Road Palo Alto, CA 94304 (650) 857-3967, fax (650) 857-7029 http://www.hpl.hp.com/personal/Alan_Karp