Title :
Local names in SPKI/SDSI
Author_Institution :
Dept. of Comput. Sci., New York Univ., NY, USA
Abstract :
We analyze the notion of “local names” in SPKI/SDSI. By interpreting local names as distributed groups, we develop a simple logic program for SPKI/SDSI´s linked local-name scheme and prove that it is equivalent to the name-resolution procedure in SDSI 1.1 and the 4-tuple-reduction mechanism in SPKI/SDSI 2.0. This logic program is itself a logic for understanding SDSI´s linked local-name scheme and has several advantages over previous logics. We then enhance our logic program to handle authorization certificates, threshold subjects, and certificate discovery. This enhanced program serves both as a logical characterization and an implementation of SPKI/SDSI 2.0´s certificate reduction and discovery. We discuss the way SPKI/SDSI uses the threshold subjects and names for the purpose of authorization and show that, when used in a certain restricted way, local names can be interpreted as distributed roles
Keywords :
authorisation; logic programming; message authentication; public key cryptography; 4-tuple-reduction mechanism; SPKI/SDSI; Simple Distributed Security Infrastructure; Simple Public Key Infrastructure; authorization; authorization certificates; certificate discovery; certificate reduction; distributed groups; distributed roles; linked local-name scheme; local names; logic program; name-resolution procedure; threshold subjects; Authorization; Computer science; Data structures; Electrical capacitance tomography; Java; Logic programming; Permission; Postal services; Privacy; Public key;
Conference_Titel :
Computer Security Foundations Workshop, 2000. CSFW-13. Proceedings. 13th IEEE
Conference_Location :
Cambridge
Print_ISBN :
0-7695-0671-2
DOI :
10.1109/CSFW.2000.856921