|
Re: example: secure computing kernel needed: msg#00206encryption.general
That is the difference, but my point is that the result with respect to the control of your computer is the same. The distant end either communicates with you or it doesn't. In authentication, the distant end uses your identity to make that decision. In remote attestation, the distant end uses your computer's configuration (the computer's identity to some degree) to make that same decision. As a result, remote attestation enables some applications that strong My statement was that the two are similar to the degree to which the distant end has control over your computer. The difference is that in remote attestation we are authenticating a system and we have some assurance that the system won't deviate from its programming/policy (of course all of the code used in these applications will be formally verified :-)). In user authentication, we're authenticating a human and we have significantly less assurance that the authenticated subject in this case (the human) will follow policy. That is why remote attestation and authentication produce different side effects enabling different applications: the underlying nature of the authenticated subject. Not because of a difference in the technology.
Well- biometrics raises some interesting Gattica issues. But, I'm not going to go there on the list. It is a discussion that is better done over a few pints. So to summarize- I was focusing only on the control issue and noting that even though the two technologies enable different applications (due to the assurance that we have in how the authenticated subject will behave), they are very similar in nature. --------------------------------------------------------------------- --------------------------------------------------------------------- The Cryptography Mailing List Unsubscribe by sending "unsubscribe cryptography" to majordomo@xxxxxxxxxxxx |
|
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| Previous by Date: | Re: Non-repudiation (was RE: The PAIN mnemonic): 00206, Ed Gerck |
|---|---|
| Next by Date: | Re: Ousourced Trust (was Re: Difference between TCPA-Hardware and a smart card and something else before: 00206, Peter Gutmann |
| Previous by Thread: | Re: example: secure computing kernel neededi: 00206, David Wagner |
| Next by Thread: | Re: example: secure computing kernel needed: 00206, Seth David Schoen |
| Indexes: | [Date] [Thread] [Top] [All Lists] |
| News | FAQ | advertise |