Distributing trust with the Rampart toolkit
Michael K. Reiter · Communications of the ACM · 1996
The Rampart group communication protocols are designed to distribute trust among a group of nodes in a distributed system-so while individual nodes need not be fully trusted, the group can be. Many mechanisms for enforcing security policy in distributed computer systems rely on trusted nodes, that is, computers and resident software whose correct functioning is essential to implementing the policy.In this article, we describe our research on distributing trust among a group of nodes, so while no single node need be fully trusted, the function performed by the group can be.Central to this effort is a toolkit of group communication protocols called Rampart we developed to simplify construction of such groups.An overarching goal of computer security mechanisms is to limit the extent to which each component of a system must be trusted to implement a desired security policy.Typically, this goal leads to system designs in which components are labeled