Authorization Certificate - Comparison of Attribute and Public Key Certificates

Comparison of Attribute and Public Key Certificates

AC is similar to PKC except that AC contains no public key because an AC verifier is under the control of the AC issuer, and therefore, trusts the issuer directly by having the public key of the issuer preinstalled. This means that once the AC issuer's private key is compromised, the issuer has to generate a new key pair and replaces the old public key in all verifiers under its control with the new one.

In addition to the absence of a public key, AC does not refer to the holder directly using identity information like in PKC but indirectly using the PKC. This means that the verification of an AC requires the presence of the PKC that is referred as the AC holder in the AC.

Similar to PKC, AC can be chained to delegate attributions. For example, an authorization certificate issued for Alice authorizes her to use a particular service. Alice can delegate this privilege to her assistant Bob by issuing an AC for Bob's PKC. When Bob wants to use the service, he presents his PKC and a chain of ACs starting from his own AC issued by Alice and then Alice's AC issued by the issuer that the service trusts. In this way, the service can verify that Alice has delegated her privilege to Bob and that Alice has been authorized to use the service by the issuer that controls the service. RFC 3281, however, does not recommend the use of AC chains because the complexity in administering and processing the chain is not worth the effort and there is little use of AC in the Internet.

Read more about this topic:  Authorization Certificate

Famous quotes containing the words comparison of, comparison, attribute, public and/or key:

    When we reflect on our past sentiments and affections, our thought is a faithful mirror, and copies its objects truly; but the colours which it employs are faint and dull, in comparison of those in which our original perceptions were clothed.
    David Hume (1711–1776)

    Certainly there is not the fight recorded in Concord history, at least, if in the history of America, that will bear a moment’s comparison with this, whether for the numbers engaged in it, or for the patriotism and heroism displayed.
    Henry David Thoreau (1817–1862)

    Essential truth, the truth of the intellectualists, the truth with no one thinking it, is like the coat that fits tho no one has ever tried it on, like the music that no ear has listened to. It is less real, not more real, than the verified article; and to attribute a superior degree of glory to it seems little more than a piece of perverse abstraction-worship.
    William James (1842–1910)

    The public seldom forgive twice.
    Johann Kaspar Lavater (1741–1801)

    All meanings, we know, depend on the key of interpretation.
    George Eliot [Mary Ann (or Marian)