| |
How can Sesame cards protect gold from Ali Baba?
A professional account must be available at all times, but proper protection is also important. Security and accessibility are sometimes conflicting requirements, but Sesame can solve that.
Ali Baba was lucky enough to spy upon 40 bandits who kept their gold in a vault that was protected only with a fixed password. Overhearing it once was enough to take gold from that vault.
Any large amount of gold should be protected from removal with a secure smart card that produces varying codes in a seemingly random order. This is what the Sesame cards do.
Had the 40 bandits protected their gold from prying ears like Ali Baba's, they might have had another problem to solve. What if the smart card held by the lead bandit would get destroyed in battle? Or less likely, if it would get lost? Then the gold would be so well protected that even the bandits could not reach it.
The solution to this is to add a backup card. With two cards registered under an account, but with a requirement to enter only one card's confirmation code, the access restriction still demands the use of a smart card, but there is now a backup. Ideally, this backup is separately kept, for example in the possession of another bandit.
The lead bandit may feel uncomfortable, having granted another bandit full access to the gold. No bandit can be trusted with such a large pile of gold! The solution could be to further restrict access, and always demand two cards before a removal of gold is granted.
To retain the level of backup, this would mean registering a third Sesame card with the gold vault. In the resulting setup, any two out of three bandits can have access to the gold. No single bandit can therefore run away with as much gold as he can carry. And conspiracies are much less likely among mutually mistrusting bandits.
These approaches can be repeated at will. Every card added can either improve the backup qualities, or restrict access by demanding one more card before the gold can move around.
It would be possible for the 40 bandits to obtain one Sesame card each, and to implement any backup level they desire. For example, when 21 Sesame cards are registered as access restrictors and 19 are registered to improve backup, then any democratic majority of bandits is able to use the gold as they like. In addition to this attractive property, 19 bandits with their cards can still perish in battle and the gold would still be accessible.
Any combination of backup level B and restriction level R is possible. The trick is to get B+R Sesame cards, first add B cards for backup, and then add R cards to enhance the account's restrictions. The cards will not become known as one of the B cards or one of the R cards; all cards are equal, and any combination of R cards can be used to provide R Sesame confirmation codes to grant moving of gold.
Posted on Thu, 20 Apr 2006, 15:58.
| |
|