Reducing the Dependence of Trust-Management Systems on PKI
| dc.contributor.author | Wang, Hao | en_US |
| dc.contributor.author | Jha, Somesh | en_US |
| dc.contributor.author | Reps, Thomas | en_US |
| dc.contributor.author | Schwoon, Stefan | en_US |
| dc.contributor.author | Stubblebine, Stuart | en_US |
| dc.date.accessioned | 2012-03-15T17:19:07Z | |
| dc.date.available | 2012-03-15T17:19:07Z | |
| dc.date.created | 2005 | en_US |
| dc.date.issued | 2005 | en_US |
| dc.description.abstract | Trust-management systems address the authorization problem in distributed systems by defining a formal language for expressing authorization and access-control policies, and relying on an algorithm to determine when a specific request can be granted. For authorization in distributed systems, trust-management systems offer several advantages over other approaches, such as support for delegation and making authorization decisions in a decentralized manner. This paper focuses on a popular trust-management system SPKI/SDSI. Although SPKI/SDSI is an attractive system for authorization in distributed systems, it has seen limited deployment. One of the major hurdles in deploying SPKI/SDSI is that it is PKI-based, i.e., every principal is required to have a public-private key pair. We present an approach that combines SPKI/SDSI with a widely-deployed authentication system, Kerberos, to reduce reliance of SPKI/SDSI on PKI. In our approach, only sites need public-private key pairs. We believe that reducing the reliance of SPKI/SDSI on PKI will facilitate its wider deployment. We also have implemented a prototype of our technique. | en_US |
| dc.format.mimetype | application/pdf | en_US |
| dc.identifier.citation | TR1527 | en_US |
| dc.identifier.uri | http://digital.library.wisc.edu/1793/60440 | |
| dc.publisher | University of Wisconsin-Madison Department of Computer Sciences | en_US |
| dc.title | Reducing the Dependence of Trust-Management Systems on PKI | en_US |
| dc.type | Technical Report | en_US |
Files
Original bundle
1 - 1 of 1