Chess grandmaster problem of zero knowledge proof of identity

From: Vladimir Shabanov (virl_at_mail.ru)
Date: 01/31/05


Date: 31 Jan 2005 07:06:33 -0800

Greetings!

I'm exploring of using zero knowledge proofs for identification.
There is so-called "grandmaster problem" (when Carol with help of Bob
can identify herself as Alice in Dave's shop; or when bad authentication
server can authenticate itself as your on third-side during your
authentication on it).

Bruce Schneier in his book "Applied Cryptography" in chapter 5.2 mentions
two solutions of this problem: "Faraday box" (when "auth. server" is
limited in communications to third parties) and using of clock (when "auth.
server" is limited in response time).

Do you know any other solutions of this problem?

I am trying to solve this problem and seeking for already
present solutions (because I don't want to reinvent a bicycle).

Best regards,
Vladimir Shabanov mailto:virl@mail.ru
P.S. Sorry for my English. It is not my native language.



Relevant Pages

  • Re: Properly configuring SMTP Service
    ... server, but no one else. ... you) to "anonymous" as an SMTP authentication method, ... SMTP protocol is very specific about where and what authentication ... the SMTP AUTH mechanisms that your server will support. ...
    (microsoft.public.inetserver.iis.smtp_nntp)
  • Re: Default authentication scope
    ... If you use Basic or Digest, authentication you can specify a default domain, ... If you are using IWA auth, then add the server to the user's Intranet ... I maintain a Windows Server 2003 member server in an active directory. ...
    (microsoft.public.windows.server.setup)
  • PEAP based 802.1x LAN authentication
    ... I am currently trying to configure an Active Directory (w2K server) ... I have successfully tried 802.1x with auth methods ... I should install MS CA and generate a certificate for the win2K server ... used with this Extensible Authentication Protocol". ...
    (Focus-Microsoft)
  • Re: Watchguard FireBox
    ... >> I also really like the auth ability. ... >> authentication can be done based on your NT/2000 groups and users. ... by NT Server and under HTTP/ALLOW putting InternetUsers. ...
    (comp.security.firewalls)
  • Re: Kerberos machine authentication - apparent authentication fail
    ... > until logon), the wireless connection can kick off when it is ready. ... > was confirmed in the server event logs with IAS (i set that up as the radius ... > as an ordinary user kicks in and takes over from the machine authentication. ... > while the network sorts itself out and a double click on a network link of ...
    (microsoft.public.windows.server.security)