Identity/CryptoIdeas/03-ID-Attached-Data: Difference between revisions

m
(Created page with "== ID-Attached Data == * Brian Warner, 05-Feb-2013 Summary: a design to extend the ideas in BrowserID Key Wrapping and Identity/CryptoIdeas/02-Recoverable-Keywrapping t...")
 
Line 96: Line 96:


* deliver a BrowserID Assertion and the token to the storage server
* deliver a BrowserID Assertion and the token to the storage server
* the storage server records a database row with the assertion's email
* the storage server records a database row with the assertion's email address, the token, and a slot where ciphertext will be stored
  address, the token, and a slot where ciphertext will be stored
* discard the assertion. The API retains kA/kB/kC and thus the ability to regenerate the token and encryption keys.
* discard the assertion. The API retains kA/kB/kC and thus the ability to
  regenerate the token and encryption keys.


[[File:PICL-04-provisioning.png|Provisioning]]
[[File:PICL-04-provisioning.png|Provisioning]]
Confirmed users
471

edits