1st Annual PKI Research Workshop---Proceedings
Carl M. Ellison · 2002
This paper contrasts the use of an ID PKI (Public Key Infrastructure) with the use of delegatable, direct authorization. It first addresses some commonly held beliefs about an ID PKI – that you need a good ID certificate to use digital signatures, that the ID certificate should come from a CA that has especially good private key security, that use of the ID certificate allows you to know with whom you’re transacting and that the combination gives you non-repudiation. It then identifies flaws in those assumptions and addresses, instead, the process of achieving access control – either through an ACL plus ID, or directly. It then applies each method of achieving access control to two examples – one within a large company and one between companies. [This paper is an expanded transcript of the invited talk of the same title prepared for the Internet-2 1 Annual PKI Workshop, which was held at NIST at the end of April 2002.]