Re: Google Docs as capabilities as data
Domenico Rotondi <[email protected]>
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <[email protected]> |
On 29 Jan 2014 at 15:35, Bill Frantz wrote: Hi Bill, I agree the SPKI has similarities with our system (indeed we were aware of it and we mention it in our papers). We too have expiration time in a capability token. The revocation mechanism has been designed to manage situation in which you need to revoke 1+ token(s) before their expiration date (e.g., the maintenance team manager in company X has compromised is private X509 key; so there is the need to revoke all capability tokens he/she has created to avoid fake tokens). Ciao Domenico > On 1/29/14 at 1:15 AM, [email protected] (Domenico Rotondi) wrote: > > > The generated tokens can be distributed to their owners using any means (even via a > > public FPT service, being each token digitally signed and boud to a specific identity). > > Each owner of a capability token can further frealy create additional tokens for other > > subjects he/she trust granting a subset of the rights he/she owns (of course if his/her > > token grants him/her the right to delegate). > > Some of this description sounds like SPKI: > > SPKI Certificate Theory - RFC 2693 > SPKI Requirements - RFC 2692 > > SPKI did revocation through the expiration of the certificate. > > Cheers - Bill > > -------------------------------------------------------------- > Bill Frantz | There are now so many exceptions to the > 408-356-8506 | Fourth Amendment that it operates only by > www.pwpconsult.com | accident. - William Hugh Murray >