Re: Hand Waving vs. Rigorous Analysis... (was Security Engineeringvs. Crypto Academics...)
From: Lassi Hippeläinen (lahippel_at_ieee.orgies.invalid)
Date: 09/15/04
- Next message: Aatu Koskensilta: "Re: Riemann hypothesis and factoring"
- Previous message: Lassi Hippeläinen: "Re: "Perfect" or "Provable" security both crypto and non-crypto?"
- In reply to: Ernst Lippe: "Re: Hand Waving vs. Rigorous Analysis... (was Security Engineeringvs. Crypto Academics...)"
- Next in thread: Ernst Lippe: "Re: Hand Waving vs. Rigorous Analysis... (was Security Engineeringvs. Crypto Academics...)"
- Reply: Ernst Lippe: "Re: Hand Waving vs. Rigorous Analysis... (was Security Engineeringvs. Crypto Academics...)"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Wed, 15 Sep 2004 06:35:06 GMT
Ernst Lippe wrote:
<...>
> There are two major weaknesses in this system, and they are not at all related
> to key management as I understand the term. First, permission management for
> a large user group is very difficult from an organizational point of view. Any
> modifications to the permission databased should only be made by authorized
> personel.
This is a real problem. The real fun begins, when support for dynamic
membership is added to the game. New members may join the group in the
middle of a session, and old members may be revoked. I haven't seen any
working system where those actions could be done in real time. Usually
the stream is broken to fragments with a separate key, and the keys are
distributed to members as late as possible. Still there is a time
window, when authorised recipients (the new members) can't receive the
stream, and unauthorised ones (revoked members) can.
-- Lassi
- Next message: Aatu Koskensilta: "Re: Riemann hypothesis and factoring"
- Previous message: Lassi Hippeläinen: "Re: "Perfect" or "Provable" security both crypto and non-crypto?"
- In reply to: Ernst Lippe: "Re: Hand Waving vs. Rigorous Analysis... (was Security Engineeringvs. Crypto Academics...)"
- Next in thread: Ernst Lippe: "Re: Hand Waving vs. Rigorous Analysis... (was Security Engineeringvs. Crypto Academics...)"
- Reply: Ernst Lippe: "Re: Hand Waving vs. Rigorous Analysis... (was Security Engineeringvs. Crypto Academics...)"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|