Describe the differences between a hierarchical PKI and one that relies on a web of trust.
Answer: Hierarchical PKIs rely on a Certificate Authority (CA) to assert the identity of a user or a server. This is typically how most people use HTTPS web-servers: you trust your bank's website because its certificate can be verified against a CA certificate which is trusted by your browser. What is perhaps less-widely known is the use of client-side certificate authentication. In this case, not only the server presents a certificate to the user, but the user also presents a certificate (for which he/she has a private key) to the server. If the server trusts the CA certificate that issued the certificate of the user, then it's a valid form of authentication. Again, this requires the user to have been delivered a certificate signed by a CA that the server trusts.
the main difficulty is in the legal and administrative process whereby the authority operates and delivers certificates. There are a number of commercial CAs (Verisign, Thawte, ...) which most browsers trust by default: there certificates are already in the browser when you obtain it. The price required to be delivered a certificate vary depending on various attributes that can be in the certificate, on the CA, and on how far they've actually been to check that the users are who they say they are. Some institutions also provide this service for free.
A FOAF+SSL authentication mechanism would make it possible to avoid depending on a small number of CAs, and instead relies on a FOAF network to assert identity. This works along the lines of a Web-of-Trust (WoT) model.
The hierarchical PKI model is fairly simple to evaluate. The network of trust can be modelled as a tree, the root of which is the CA certificate; the chain is built between the leaf (the user certificate) to the root of the tree. This is also because CAs come with policies that specify which certificates intermediate CAs are allowed to sign so that the chain is valid.If we want to use a Web-of-Trust model, we need to provide a new way to evaluate trust, and to model this in the FOAF extensions.The hierarchical PKI model is fairly simple to evaluate. The network of trust can be modelled as a tree, the root of which is the CA certificate
Another problem is that, in the CA model, a root CA or any intermediate in the chain is something for which:
There are usually legal documents and policies in certificate authorities that define these agreements.
One must be quite careful in a Web-of-Trust model to make sure that this distinction is integrated in the function that evaluates trust. Trusting someone's identity and trusting someone's actions are rather distinct things. On the one hand, this can bring more complexity; on the other hand, this can bring more power to the model.
in a hierarchical PKI. The identity of the user could still be valid, thus authentication would work well, you would just want to deny authorisation. In the case of Web-of-Trust, this can be a bit more tricky, since you may have to re-evaluate the assertions you've made about his friends.
Describe the differences between a hierarchical PKI and one that relies on a web of trust.
State similarities and differences between Fuzzy c-means and hierarchical clustering based on Gaussian distributions.
Describe how PGP public keys are distributed to establish a trust relationship comparing it with the approach taken for the Public Key Infrastructures (PKI)
What are the major differences between a web application and a windows application? What are the advantages and disadvantages of Web-based systems and windows-based systems? Why would you use one instead of the other?
they a lack of trust between trading partners as one of the main obstacles to fully achieving integration. Describe some of the reasons why a company may not trust its suppliers, and suppliers might not trust their business customers. Then describe what each party can do to build trust.
Between Ward’s method and the centroid method for hierarchical clustering, which one can be considered the hierarchical counterpart of the (partitional) K-means?
Describe similarities and differences between subjective relativism and ethical egoism. (4%) 9: Describe similarities and differences between divine command theory and Kantianism. (4%) 10: Describe similarities and differences between subjective relativism and act utilitarianism. (4%) 11: Describe similarities and differences between Kantianism and rule utilitarianism. (4%)
xQ4. Describe the differences between the 2 models used to describe enzyme mechanisms of action and explain why one can is useful to describe both competitive and non-competitive enzyme inhibition and one can only describe competitive inhibition. re ill of
xQ4. Describe the differences between the 2 models used to describe enzyme mechanisms of action and explain why one can is useful to describe both competitive and non-competitive enzyme inhibition and one can only describe competitive inhibition. re ill of
Describe the differences between correlations and regressions. Can you describe situations where you would use one of these over the over, and why you would do so?
Describe the differences between the use of the binomial and Poisson distribution. Provide one example of how each can be used and explain why you selected the example.
Describe the differences between digital crimes and hackers. Are there differences? If there are or if there are not, discuss your views in your own words.