Re: Opaque storage

Marcus Brinkmann <[email protected]>
Newsgroups gmane.os.hurd.l4
Message-ID <87lkkd77o7.wl%[email protected]>
At Mon, 08 Jan 2007 12:02:57 -0500,
"Jonathan S. Shapiro" <[email protected]> wrote:
> 
> I propose that we change the subject line on this discussion.
> 
> Can somebody remind me how, in a system providing only translucent
> storage allocation, one can safely manage the private portion of a
> cryptographic key?
> 
> I do remember that we discussed this. I do not remember what the
> proposed resolution was.

It depends on what you mean.  If the example is that the user has a
key which he wants to hide from the applications, then he puts the key
into its own application, and provides only access via service
invocation, not process instantiation.

The other way around, ie applications hiding the key from the user, is
not possible of course.

In general theapproach is to replace process instantiation with
service invocation.

Thanks,
Marcus
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.