Re: Logotypes in certificates

Dean Povey <povey@dstc.qut.edu.au> Tue, 20 March 2001 02:07 UTC

Received: from above.proper.com (above.proper.com [208.184.76.39]) by ietf.org (8.9.1a/8.9.1a) with SMTP id VAA29930 for <pkix-archive@odin.ietf.org>; Mon, 19 Mar 2001 21:07:12 -0500 (EST)
Received: from localhost by above.proper.com (8.9.3/8.9.3) with SMTP id SAA25618; Mon, 19 Mar 2001 18:06:39 -0800 (PST)
Received: by mail.imc.org (bulk_mailer v1.12); Mon, 19 Mar 2001 18:06:32 -0800
Received: from thunder.dstc.qut.edu.au (thunder.dstc.qut.edu.au [131.181.71.1]) by above.proper.com (8.9.3/8.9.3) with ESMTP id SAA25587 for <ietf-pkix@imc.org>; Mon, 19 Mar 2001 18:06:29 -0800 (PST)
Received: from dstc.qut.edu.au (garnet.dstc.qut.edu.au [131.181.71.36]) by thunder.dstc.qut.edu.au (8.10.1/8.10.1) with ESMTP id f2K26Qm20775; Tue, 20 Mar 2001 12:06:26 +1000 (EST)
Message-Id: <200103200206.f2K26Qm20775@thunder.dstc.qut.edu.au>
X-Mailer: exmh version 2.2 06/23/2000 with nmh-1.0.4
cc: Rich Salz <rsalz@zolera.com>, ietf-pkix@imc.org, ajosang@dstc.edu.au
Subject: Re: Logotypes in certificates
In-Reply-To: Message from Dean Povey <povey@dstc.qut.edu.au> of "Tue, 20 Mar 2001 11:20:38 +1000." <200103200120.f2K1Kgm20434@thunder.dstc.qut.edu.au>
Mime-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Date: Tue, 20 Mar 2001 12:06:26 +1000
From: Dean Povey <povey@dstc.qut.edu.au>
X-MIME-Autoconverted: from quoted-printable to 8bit by above.proper.com id SAA25588
Precedence: bulk
List-Archive: http://www.imc.org/ietf-pkix/mail-archive/
List-ID: <ietf-pkix.imc.org>
List-Unsubscribe: mailto:ietf-pkix-request@imc.org?body=unsubscribe
X-MIME-Autoconverted: from 8bit to quoted-printable by above.proper.com id SAA25618
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by ietf.org id VAA29930

>I should have explained.  It only works if the browser does something 
>sensible like displays the logo in a prominent place where the user will 
>notice and which can't be recreated by just straight HTML.  Kind of like 
>the way the lock clicks on to tell you you have a secure connection.  
>Presumably the CA will perform some due-dilligence when certifying company 
>logos.

To make the scheme clearer, one of the other authors on the first paper I
mentioned has recommended a more recent paper with more detail.

A. Jøsang, M.A. Patton and A. Ho. Authentication for Humans. In the
Proceedings of the 9th International Conference on Telecommunication Systems.
Dallas, March 2001. http://security.dstc.edu.au/papers/authum.pdf

Cheers.
-- 
Dean Povey,         | e-m: povey@dstc.edu.au | JCSI:  Java Crypto Toolkit 
Research Scientist  | ph:  +61 7 3864 5120   | uPKI:  C PKI toolkit for embedded
Security Unit, DSTC | fax: +61 7 3864 1282   |        systems
Brisbane, Australia | www: security.dstc.com | Oscar: C++ PKI toolkit