Free Newsletters
Technology & Business Daily

InfoWorld
Log-in | Register

CoreStreet targets massively scalable validation

Phil Libin

By Jon Udell  
May 21, 2004
 

All computer and network security begins with authentication. Once you identify someone, by whatever means, the focus shifts to authorization, or what CoreStreet’s President Phil Libin calls validation. Are the credentials still valid? Is the authenticated person allowed to read this document or enter that airplane cockpit?

Free IT resource

Virtualization Insights from Top Experts - Learn how virtualization gets real!

Sponsored by Dell

Free IT resource

TechNet: More ways to know it, share it, and keep it running.

Sponsored by Microsoft

DOWNLOAD PDF

Click here to download InfoWorld's special report InfoWorld Innovators 2004


In small-scale connected systems, we just look up the person in a directory and check permissions. But when there are millions of potential readers of the document, or when the plane is airborne and can’t contact the directory, we’re stuck. It hasn’t been feasible, never mind economical, to validate credentials on a massive scale across far-flung and/or occasionally connected networks. Libin wants to do for validation what GPS does for location-finding: Make it cheap and ubiquitous.

The vision unfolds in several phases. CoreStreet’s RTC (Real Time Credentials) Validation Authority precomputes and distributes OCSP (Online Certificate Status Protocol) responses, working with existing public key infrastructure. The Department of Defense, Libin says, is rolling out this solution to validate credentials on its more than four million Common Access Cards.

In other applications, the RTC generates and distributes small packets of data — time limited and tamper evident — that can safely travel to the edge of the network or even beyond to offline devices. The mathematical foundations were laid by CoreStreet’s chief scientist, Silvio Micali, who won the 1993 Gödel Prize for his theoretical work on zero-knowledge and interactive proofs. What Libin and his team saw in Micali’s work was a series of applications that transcend the limitations of centrally connected validation.

The security counterpart to GPS is something Libin calls “validation heartbeat.” Superdistribution of time-limited credentials, he suggests, will make validation on a massive scale both feasible and economical. In one version of the idea, VTokens transmit small sets of credentials to, for example, bandwidth-constrained battleships. In another version, MiniCRLs (Certificate Revocation Lists) broadcast huge batches of credentials — what Libin calls a “world file” — to, for example, routers that need to divide the vast population of IP hosts into friends and foes.

By decoupling the distribution of credentials from their generation, all these schemes challenge traditional assumptions about the bandwidth, security infrastructure, and device capabilities required in order to validate credentials. “We can see a time in the near future,” Libin says, “when an application or device can take for granted that it just knows, without having to ask, whether an action is valid.”





 


 
Jon Udell is lead analyst and blogger in chief at the InfoWorld Test Center.

  More of Jon Udell's column
  Jon Udell's Weblog

Newsletter Check out all of our free newsletters!
Enter e-mail address:




 

TOP NEWS:


»  Yahoo tells Icahn that its own board knows best
Yahoo claims that Icahn's proposal shows a 'significant misunderstanding' of how Microsoft's buyout offer was handled

»  Does Icahn have a backup plan?
Carl Icahn is trying to force Yahoo back to the bargaining table with Microsoft, but if Microsoft is no longer interested, he'll need to have other options available

»  Sprint: WiMax cleared for commercial use
Sprint has completed nearly a year's worth of testing and has now declared WiMax up to commerical deployment standards

»  Tools circulate that crack Debian, Ubuntu keys
The tools take advantage of a recently discovered vulnerability and can be used to forge digital signatures and steal confidential information

»  Facebook to Google: Friend Disconnect
Facebook cites violation of its terms of service as grounds for blocking Google's Friend Connect from accessing social network's members' data

»  U.S. to investigate semiconductor patent complaints
LSI and subsidiary Agere Systems ask ITC to bar imports by companies violating their patent for semiconductor chips containing tungsten metal




Virtualization: A Step by Step Approach to Success
Your virtual machines can be up and running in a matter of minutes. HP and Citrix have integrated XenServer with HP ProLiant servers and management tools, powered by hardware-assisted Intel Virtualization Technology to enable high- performance, cost-savings solutions for server consolidation and disaster recovery. Sponsor: HP

»  Click here to view this Webcast
  The Data Protection You've Been Looking For
Enterprise data is of supreme importance. If you can't find it quickly, it's worthless. If you lose it, it's a crisis. This IT Strategy Guide explores how to keep your data safe.

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 

FIND PRODUCTS AND COMPANIES
» COMPLETE PRODUCT GUIDE



TECHNOLOGY INDEX
• Applications
• Application Development
• Security
• Networking
• Wireless
• Platforms
• Hardware
• Data Management
• Storage
• Web Services
• Business
• Telecom
• Professional Services
• Standards

TECH WATCH 


What's the 411 on GOOG-411?
Just as Google has become synonymous with "performing a Web search," 411 is understood to mean "information" -- as in "what's the 411?" I was thus surprised to discover, from a billboard, no less, that the king of search is taking on the ...

Apple HTML source reveals 'iPhone Extreme'
"This one's a stretch..." reports AppleInsider. Um, yeah. Reporting on HTML code sightings of product names could be called a stretch, but iPhone Extreme has a ring to it. Now, that sounds like the product Apple should have released first, rather ...

COLUMNISTS

Unified under law
Ephraim Schwartz's Column and Blog (InfoWorld) - In the litigious world we live in, deploying a unified communications platform in your enterprise could...
» MORE COLUMNISTS

MORE INFOWORLD BLOGS


Open Sources 
Product Management
When I joined MySQL four years ago, there was quite a lot of debate about product management. We didn't actually have ...

Zero Day 
Botnet herders tending smaller flocks
New research backs up the theory that botnet operators are keeping their networks smaller in a continued effort to keep ...



• Advice Line
• Database Underground
• The Deep End
• Enterprise Mac
• Geeks in Paradise
• Grid Meter
• The Gripe Line
• InfoWorld Daily
• Inside IT
• IT Troubleshooter
• ITXtreme
• Open Sources
• ProdBlog
• Real World SOA
• Reality Check
• Security Adviser
• SMB IT
• The Storage Network
• Tech Watch
• Virtualization Report
• Zero Day

ADVERTISEMENT


RESOURCE CENTERadvertisement 

GOVERNMENT IT & POLICY
'If you don't go after the network, you're never going to stop these guys. Never.'
From the State Department, All the News for Inquiring Minds
TechPresident, the Internet Citizenry's New Consensus Taker



Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS  CAREERS  IT EXEC-CONNECT   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist