Local Names in SPKI/SDSI

  • Authors:
  • Ninghui Li

  • Affiliations:
  • -

  • Venue:
  • CSFW '00 Proceedings of the 13th IEEE workshop on Computer Security Foundations
  • Year:
  • 2000

Quantified Score

Hi-index 0.00

Visualization

Abstract

We analyze the notion of 驴local names驴 in SPKI/SDSI. By interpreting local names as distributed groups, we develop a simple logic program for SPKI/SDSI's linked local-name scheme and prove that it is equivalent to the name-resolution procedure in SDSI 1.1 and the 4-tuple-reduction mechanism in SPKI/SDSI 2.0. This logic program is itself logic for understanding SDSI's linked local-name scheme and has several advantages over previous logics.We then enhance our logic program to handle authorization certificates, threshold subjects, and certificate discovery. This enhanced program serves as both a logical characterization and an implementation of SPKI/SDSI 2.0's certificate reduction and discovery.We discuss the way SPKI/SDSI uses threshold subjects and names for the purpose of authorization and show that, when used in a certain restricted way, local names can be interpreted as distributed roles.