[46654] in Cypherpunks
Re: "trust management" vs. "certified identity"
daemon@ATHENA.MIT.EDU (Matt Blaze)
Sat Jan 6 20:03:23 1996
To: "Frank O'Dwyer" <fod@brd.ie>
Cc: cypherpunks@toad.com
In-Reply-To: Your message of "Sun, 07 Jan 1996 00:47:48 GMT."
<01BADC99.C7034FE0@dialup-169.dublin.iol.ie>
Date: Sat, 06 Jan 1996 20:03:11 -0500
From: Matt Blaze <mab@research.att.com>
...
>That's not to say that the certification approach can't be general, though.
>It occurred to me that a very general certificate format would
>simply be to sign some assertions (predicates), and then
>feed all available signed predicates plus some axioms (the analogue
>of root keys) into a theorem prover. Sounds slow though. More
>practically perhaps, you could sign some kind of (safe) interpreted code,
>and have the verifier execute it on some initial variable set to come up with
>some access decision.
>
Yes. That's pretty much PolicyMaker in a nutshell.
-matt