Difference between revisions of "Trust Service"
From MgmtWiki
(→Problem) |
(→Solution) |
||
| Line 13: | Line 13: | ||
*Attempts to make a trusted connection from a user to [[Web Site]] have included [[EV Cert]]s and other attempt to over come the failings inherent in trusting any connection based on the [[URL]] have all failed. See the page [[Bearer Tokens Considered Harmful]] for details. | *Attempts to make a trusted connection from a user to [[Web Site]] have included [[EV Cert]]s and other attempt to over come the failings inherent in trusting any connection based on the [[URL]] have all failed. See the page [[Bearer Tokens Considered Harmful]] for details. | ||
# Create a [[Trusted Identifier]] as a URN for web sites and then bind the token to that URN. | # Create a [[Trusted Identifier]] as a URN for web sites and then bind the token to that URN. | ||
| + | ===German Proposal for Identity and Trust Services=== | ||
| + | *[http://undocs.org/en/A/CN.9/WG.IV/WP.155 Draft Instrument on Cross-Border Legal Recognition of Identity Management and Trust Services — Proposal by Germany] | ||
==Reference== | ==Reference== | ||
Revision as of 11:57, 15 November 2018
Contents
Full Title or Meme
Any Web Site that reports on the depth of support that other sites or documents have for the principles of the Framework Profiles that they claim to support.
Context
- Any Web Site that wishes to acquire User Information should first present Assurance as to their trustworthiness to the User.
Problem
- There are few functional trust services today, for example:
- DOI
- DNSSEC
Solution
Compare with other solutions like:
- Attempts to make a trusted connection from a user to Web Site have included EV Certs and other attempt to over come the failings inherent in trusting any connection based on the URL have all failed. See the page Bearer Tokens Considered Harmful for details.
- Create a Trusted Identifier as a URN for web sites and then bind the token to that URN.