2004 · 27 citations · 7 references
We examine several architectures for extending the nascent technology of automated trust negotiation to bring nonidentity-based authentication and authorization to mobile devices. We examine how the location of trust agents and secure repositories a#ects such a system. We also present an implementation of one of these models. This protocol leverages software proxies, autonomous trust agents, and secure repositories to allow portable devices from di#erent security domains (i.e., with no pre-existing relationship) to establish trust and perform secure transactions. This proposed system is called surrogate trust negotiation as the sensitive and resource-intense tasks of authentication are performed vicariously for the mobile device by a surrogate trust agent.
7
William H. Winsborough, Kent Seamons, Vicki E. Jones · 2002 · 420 citations
Marianne Winslett, Ting Yu, Kent Seamons et al. · IEEE Internet Computing · 2002 · 258 citations
Encapsulating Security Payload (ESP)
P. Karn, William A. Simpson, Perry Metzger · 1995 · 81 citations