Trust Management systems are typically explicit in their assumption that principals are uniquely identifiable. However, the literature has not. been as prescriptive concerning the uniqueness of the permissions delegated by principals. Delegation subterfuge may arise when there is ambiguity concerning the uniqueness and interpretation of a permission. As a consequence, delegation chains that are used by principals to prove authorization may not. actually relied the original intention of all of the participants in the chain. This paper describes an extension to SPK1/SDSI that uses the notion of linked local permissions to eliminate ambiguity concerning the interpretation of a permission and thereby avoid subterfuge attacks.
展开▼