pem-dev
[Top] [All Lists]

Re: Signed objects vs. signed comments

1993-05-03 14:30:00
Ned,

        The issues that arise as one tries to associate sematics with
even simple signed objects are non-trivial.  Addison Fischer has
written some very good, pragmatic papers on these issues, in the
business arena, with a focus fiduciary applications.  The more general
context we are discussing here, with annotations and timeliness of the
annotations is even more complex.  I suggest that we not try to solve
this problem until we get the syntax straight.

        By the way, there are alternatives to a trusted third party
archive server.  A timestamp notary is one example, and Bellcore has
developed a clever technique that uses one-way hashes, but not
signatures, for the timestamp registration function.  I think the goal
for PEM and MIME-PEM is to provide a framework in which these
anciliary facilities acn be invoked, but not attempt to put too much
of the semantics into this set of standards.

Steve

<Prev in Thread] Current Thread [Next in Thread>