Re: Joins on capabilities that have passed through different membranes

Bill Frantz <[email protected]> Mon, 4 Jan 2016 18:24:01 -0800
Newsgroups gmane.comp.capabilities.general
Message-ID <r422Ps-10112i-3C1B1C4043F145EFA9FB96278E5F8733@Williams-MacBook-Pro.local>
On 1/4/16 at 5:53 PM, [email protected] (Kenton Varda) wrote:

>I'm interested to know if you've thought about the following problem:

I see a number of possibilities here. Lets assume that Alice's 
cap is A , Bob's is B, and the underling capability is C.

We can have A merge B, B merge A, or a separate merge utility M. 
M can either be in cahoots with the Revoker front ends Ra and Rb 
or not.

If R has the authority to look inside other instances of itself, 
Ra can look at Rb and determine that the Ra' C is the same as 
Rb's C and "Do the right thing"tm.

If M is in cahoots with Ra and Rb, it can perform the same magic.

If all are independent, there may be some varient of the Ask Bob 
Protocol which applies, bringing C into the act.

I would say that if either A or B is revoked, then M should not 
perform a merge. (I hope A or B are revoked enough that Ra and 
Rb can't perform a merge either.)

The life span of the result of the merge D is interesting. If it 
has the same authority as A or B, then either would do as the 
result of the merge. If it has more authority, then A and B 
represent something more than a revokable version of C.

Cheers - Bill

-------------------------------------------------------------------------
Bill Frantz        | Airline peanut bag: "Produced  | Periwinkle
(408)356-8506      | in a facility that processes   | 16345 
Englewood Ave
www.pwpconsult.com | peanuts and other nuts." - Duh | Los Gatos, 
CA 95032