Re: Opaque storage

Pierre THIERRY <[email protected]>
Newsgroups gmane.os.hurd.l4
Message-ID <[email protected]>
Scribit Marcus Brinkmann dies 10/01/2007 hora 09:15:
> This "destined to S" in your proposal appears to be exactly the
> tagging that I proposed.  Don't you think so?

Not at all. It's a consideration for the readers of the scenario to
understand what is happening, and nothing in the system has knowledge of
it.

No tagging takes place in my scenario. Instead, only the graph of
capabilities dictate who is able to use the opaque storage capability.

S is just naturally outside the reference monitor, so when B invokes s1
to send the c1 capability, G substitute c0 to c1, and S receive the
opaque storage capability.

Note that G has no knowledge anywhere of the processes in or out of the
reference monitor. It's only because B in the first place asks A by the
way of G that it receives mediated capabilities.

> To implement identity based access control, when a program A wants to
> proof to a peer B that it has access to an identity without actually
> handing it to B.

And where is identity based access control needed?

Curiously,
Nowhere man
-- 
[email protected]
OpenPGP 0xD9D50D8A

_______________________________________________
L4-hurd mailing list
[email protected]
http://lists.gnu.org/mailman/listinfo/l4-hurd
signature.asc (application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFFpQooxe13INnVDYoRApERAJ9trJNCQj6r20tPidniQPJUZD5EQgCggZY3
Qkhumi2MJYDpva/hkB060/8=
=R0Wf
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.