[46786] in Cypherpunks
Re: Certificates: limiting your liability with reuse limitations
daemon@ATHENA.MIT.EDU (Adam Shostack)
Mon Jan 8 18:43:53 1996
From: Adam Shostack <adam@homeport.org>
To: cypherpunks@toad.com
Date: Mon, 8 Jan 1996 18:39:44 -0500 (EST)
In-Reply-To: <199601082310.SAA27803@thor.cs.umass.edu> from "Futplex" at Jan 8, 96 06:10:01 pm
A. Michael Froomkin writes:
> I know I can put an expiration date on the certificate, but that's not
> enough. I can accumulate a lot of exposure in a few seconds, much less
> weeks.
>
> I know I can put a reliance limit in the X.509 ver 3 certificate, but
> that's not enough. Even a $1 limit could be used many millions of times.
>
> Is it feasabile to say: Can only be relied on once per day/week/month?
Undeniable digital signatures. They're not 'undeniable'
differently from normal digital signatures, but they do require the
cooperation of the signer to confirm the signature. Thus, a KCA could
decide only to verify a signature 50 times, or once per day (or once
per being paid the $10 signature verification fee.)
Schneier has a decent amount on undeniable digital signatures.
Adam
--
"It is seldom that liberty of any kind is lost all at once."
-Hume