TweetFollow Us on Twitter

What is Cryptography Good For?

Volume Number: 13 (1997)
Issue Number: 11
Column Tag: Dialog Box

What Is Cryptography Good For, Anyway?

by Robert Hettinga, Boston

A look at why the market demands cryptography, because it makes electronic business more efficient

Cryptography allows you to do business with, work with, and trust people you don't know. It can also save a lot of time, programming, and machine resources, and thus, money.

Many people who talk about cryptography talk about it in political terms. We hear people talk about civil liberties, about freedom of speech, the right to bear "arms" (crypto is classified as a munition) or even freedom from having the government quarter "troops", in the form of key escrow authorities, on our hard drives. Frankly I've gotten tired of all the politics. Cryptography, like any other technology, is value neutral. Just like any form of progress, cryptography won't be adopted unless it makes our lives better. And that, I assure you, is what it is going to do.

I've talked extensively in speeches, on the net, and in articles like this one, about financial cryptography and how it's going to change the world, not by making our transactions invisible to big brother, but by forcing profit and loss responsibility down onto smaller and smaller organizations, and, eventually, to applications and microprocessors themselves. I joke about the day when, instead of a credit card association and a bank loaning us money for lunch, it will be a syndicate of individual "bond-bots" each taking a small piece of what could be called a personal digital bearer bond issue for that lunch, all based on our reputation and ability to repay.

I talk about routers which would move information around the net by charging minuscule bits of picocash, buying bandwidth low and selling it high -- sender pays -- in an instantaneously settled auction market for packet switching. Good bye to peering fights, NAPs, and the emerging hierarchy of super-routers and high-capacity backbones. Since each router makes money instead of costs money, it behooves routers to be connected to several other routers, creating a geodesic, instead of hierarchical, Internet. When a router saves enough money out of operations, it could buy a copy of itself. This whole idea of a self-organizing ecology of microeconomic entities makes a lot of people yell at me, particularly those who've spent their careers building bigger and bigger systems, but, then, as my friend Rodney Thayer says, "you're only as good as the people who yell at you". Since I've had some pretty clueful people yell at me, I must be on to something.

Financial Basics

Let's start with a little finance. It will help us understand things a little better.

One of the pervasive notions in the economy is that of the book entry. Modern double-entry bookkeeping is about keeping debits and credits in a database. Most of our transaction systems are about sending these debits and credits over wires: credit cards, checks, and almost all transaction settlement in the capital markets are all done with book-entry settlement. Try asking your broker for physical delivery of a stock certificate sometime, and you'll see what I mean.

We have book-entry settlement now because when telegraphy was invented, you couldn't send a bearer certificate, like those old fashioned bonds with rows of coupons on the bottom -- or paper money -- down a wire. We could send only stuff like "I'm debiting this amount from my account, please credit yours by the same."

One problem with book-entries is that you have to trust who sent them to you. This is usually done with access control lists and private proprietary networks. "Clubs" if you will, with a list of members, all biometrically identified (the SEC doesn't take fingerprints for fun), and strict rules for doing things with other members of the club. Break the rules and get thrown out of the club, or worse.

This is different from bearer certificates. With a bearer certificate, you can tell by inspection that the certificate is valid, and, if you know the public reputation of the person or company who issued the certificate, you can decide whether or not to trust them. For example, you can pretty much tell that a dollar bill is genuine by inspection, and you can trust that a modern dollar bill is worth something, but that a Confederate dollar isn't, simply by knowing the public reputation of the issuer.

Another problem with book-entries is that because they are basically unsecure transactions sent down a secure network, we have to have some kind of sanction to prevent fraud. By "sanction" we usually mean violence, usually "sold" by a nation-state of some kind. Nick Leeson, who recently brought down Barings Bank, was sent to jail for making the wrong book-entry. (They tried in Singapore but he escaped to Germany and was extradited to Britain.) Of course, if you send a book-entry to a machine in St. Louis, but you're in Kampala, there's a problem. The answer, of course, is a global government and police force. Right. Go look up Occam's Razor in the dictionary for an answer to that one...

With a bearer certificate, you can shun people who cheat you, which, in some ways, is better than violent sanction. It's certainly cheaper. Ask the Amish how well shunning works as social control. In a financial market, shunning is economic death. Nobody will do business with you.

The very biggest problem with digital book-entries is that they cost so much, and I don't mean just in paying taxes to support police. I mean in computer processing and storage. Not only must we keep lists of who can do what to whom and for how much, we also have to keep records of what we did with anybody else, so we can bust them for doing something wrong to us later. Also, for every transaction regime, there must be a trusted third party, usually called a clearinghouse, who has records of what everybody did to everybody else. On a typical credit card transaction, for instance, you, me, your bank, my bank, and the credit card company all have a record of the lunch I bought from you. We aren't even talking about the check I send to my bank monthly to actually settle my credit card transactions.

We also won't talk about the fact that anyone who scored high enough on a civil service test and now works at the Financial Crimes Enforcement Network (FinCEN) has the right to see those transactions. That's because, again, heretical as it is to the civil liberties folks, cryptography is not really about privacy. It's about economic efficiency and progress.

Creating Digital Bearer Certificates

How can we send a bearer certificate down a wire? Because we can now create digital bearer certificates using the blind signature algorithm developed by David Chaum, the founder of DigiCash. Using this algorithm I can create a unique cryptographic object which has value in the same way that a dollar bill is a unique printed object having value. Of course, those cryptographic objects can be moved down a wire.

Moore's Law dictates a more geodesic network by automating switching and dropping its cost in half every 18 months. It also allows us to pay for that switching very efficiently, by allowing us to automate and manipulate blind signatures and other cryptographic algorithms very cheaply. We, or better, our machines, can issue and spend these bearer certificates of any transaction size, from trillions of dollars to trillionths of a cent, all without keeping transaction records or access lists.

Pull the change out of your pocket and look at it. Do you remember where each and every coin came from? Do you care? When you spend them in a soda machine, does it care? No. Imagine a world where the soda machine or the Internet takes VISA. And, no, I don't mean of big brother, either. Imagine if the whole net cleared on a 90 day float time, at 18% interest... It's absurd. But, of course, I'm still not really here to talk about financial cryptography. I'm here to talk about access control.

Controlling Access with Bearer Certificates

Well, suppose you had some code you wanted to limit access to, say the SubWoofer source code, or maybe beta version of your software. Suppose, instead of creating and managing a list of developers and what they can see, or even passing around an easily compromised password, you just handed each of them a unique cryptographic object. A ticket, if you will. People could download the package, but only if they cashed in a ticket for it.

The neat thing about this idea is that you don't care who shows up with a ticket, because the tickets are unique and unreplicable. They have value, the value of one download of the SubWoofer source. You can e-mail them out, and if the person who receives the ticket doesn't use it and gives it to someone else, you still have issued only a finite number of copies of the code. Anyone who shows up with a duplicate ticket doesn't get the package. If you're really draconian, Chaum's protocol lets you take the "double-spent" ticket, compare it with the ticket you have taken in already, and identify the key which duplicated the ticket. No access control lists, but you still have to hang onto the tickets which have been turned in.

There are other problems, too. The above actually involves setting up a Chaumian mint and having patented, signature-blinding walletware. Unfortunately, DigiCash, like Chaum before them, have been playing dog in the manger with the patent and are not licensing it to people who could actually make some use of it. There has always been a problem of mistaken identity at DigiCash. First they thought they were CitiCorp, then they thought they were Microsoft, now they think they're VISA. Someday they'll wake up and realize they're cryptographers, or possibly Dolby and Co. (the audio technology people), and we'll all be better off for it.

Fortunately, there is an almost equivalent way to get the same result with minor modifications to an existing, public code base: PGP. It should be possible to do the following neat hack, a sort of a poor man's certification authority. Actually, we're creating something more important than a hierarchical "authority", we're creating a small, geodesic, "web" of trust. First, create a private PGP key which authorizes people to access the package. (PGP allows you to generate multiple private keys. Just create one for this particular "permission".) Then, using that key, digitally sign the public key of people who you want to have access, and send their signed keys to them. Now, create a quick and dirty browser plugin to hold a copy of the person's signed public key. (This also can then be used for other kinds of access signatures later.) Actually, you might as well put their signed key into the plugin and send it to them that way, since they won't have the plugin the first time around, anyway. Next, put a CGI on your webserver which reads the key in the plugin, and checks to see if it's signed by the right key. Again, this is a single key, an access control "list" which will always have one "record". Well, I suppose you might have two or three people, so you could have them each generate a special purpose key pair of their own, and store the public keys in the list of authorized signatures. Only the person who owns the key in the plugin can make the plugin work.

To use it, someone puts the plugin where their browser wants to see it, and goes to the URL you told them to. The CGI checks the "ticket pocket" plugin and sees if their signature is signed by the key which authorizes access. If not, they go to a page which tells them how to get permission. If they do have permission, then they just see the download page automatically. They can download as many copies of the package as they want, and whether they hand it around is covered, hopefully, by an NDA of some kind.

By the way, when someone talks about cryptographically "watermarking" an application, remember that all this does is tell where the code was stolen from, not who stole it. Clearly, this makes "watermarking" things a waste of time.

Anyway, once we've built the pieces, we can use this technology for anything we want to control access to. No passwords, no users accounts, no group list -- hardly any management at all. In fact, if everyone has the plugin already, all the authorizing person has to do is to download someone's public key off a keyserver somewhere and mail them a signed copy of it.

Cryptography is Easier than Bookkeeping

So now you know why cryptography is so cool, and, most especially, efficient. You don't need vulnerable and expensive databases, with probably secure but potentially unreliable session "pipes" linking them (SSL and SET for example), all to just move permissions, or decision rules, or abstractions of value -- like money -- around the net. Anytime you're confronted with a large and volatile database, especially if it requires another large list of people to have permission to change data in that list, ask yourself if you could do it all much better by creating cryptographic objects and moving them around instead of database entries.

As our ticket and certification web examples show, cryptography usually offers a better way to do it.

Occam's Cryptography, if you will. Cryptography is a weapon, remember?


Robert Hettinga, rah@shipwright.com, is a financial cryptography industry pundit. He started several e-mail lists, a web site, a monthly luncheon group, and even an annual conference in Anguilla, all to talk about financial cryptography. See the e$ web site http://www.shipwright.com/ for more information about his various services.

 

Community Search:
MacTech Search:

Software Updates via MacUpdate

Latest Forum Discussions

See All

Top Mobile Game Discounts
Every day, we pick out a curated list of the best mobile discounts on the App Store and post them here. This list won't be comprehensive, but it every game on it is recommended. Feel free to check out the coverage we did on them in the links... | Read more »
Price of Glory unleashes its 1.4 Alpha u...
As much as we all probably dislike Maths as a subject, we do have to hand it to geometry for giving us the good old Hexgrid, home of some of the best strategy games. One such example, Price of Glory, has dropped its 1.4 Alpha update, stocked full... | Read more »
The SLC 2025 kicks off this month to cro...
Ever since the Solo Leveling: Arise Championship 2025 was announced, I have been looking forward to it. The promotional clip they released a month or two back showed crowds going absolutely nuts for the previous competitions, so imagine the... | Read more »
Dive into some early Magicpunk fun as Cr...
Excellent news for fans of steampunk and magic; the Precursor Test for Magicpunk MMORPG Crystal of Atlan opens today. This rather fancy way of saying beta test will remain open until March 5th and is available for PC - boo - and Android devices -... | Read more »
Prepare to get your mind melted as Evang...
If you are a fan of sci-fi shooters and incredibly weird, mind-bending anime series, then you are in for a treat, as Goddess of Victory: Nikke is gearing up for its second collaboration with Evangelion. We were also treated to an upcoming... | Read more »
Square Enix gives with one hand and slap...
We have something of a mixed bag coming over from Square Enix HQ today. Two of their mobile games are revelling in life with new events keeping them alive, whilst another has been thrown onto the ever-growing discard pile Square is building. I... | Read more »
Let the world burn as you have some fest...
It is time to leave the world burning once again as you take a much-needed break from that whole “hero” lark and enjoy some celebrations in Genshin Impact. Version 5.4, Moonlight Amidst Dreams, will see you in Inazuma to attend the Mikawa Flower... | Read more »
Full Moon Over the Abyssal Sea lands on...
Aether Gazer has announced its latest major update, and it is one of the loveliest event names I have ever heard. Full Moon Over the Abyssal Sea is an amazing name, and it comes loaded with two side stories, a new S-grade Modifier, and some fancy... | Read more »
Open your own eatery for all the forest...
Very important question; when you read the title Zoo Restaurant, do you also immediately think of running a restaurant in which you cook Zoo animals as the course? I will just assume yes. Anyway, come June 23rd we will all be able to start up our... | Read more »
Crystal of Atlan opens registration for...
Nuverse was prominently featured in the last month for all the wrong reasons with the USA TikTok debacle, but now it is putting all that behind it and preparing for the Crystal of Atlan beta test. Taking place between February 18th and March 5th,... | Read more »

Price Scanner via MacPrices.net

AT&T is offering a 65% discount on the ne...
AT&T is offering the new iPhone 16e for up to 65% off their monthly finance fee with 36-months of service. No trade-in is required. Discount is applied via monthly bill credits over the 36 month... Read more
Use this code to get a free iPhone 13 at Visi...
For a limited time, use code SWEETDEAL to get a free 128GB iPhone 13 Visible, Verizon’s low-cost wireless cell service, Visible. Deal is valid when you purchase the Visible+ annual plan. Free... Read more
M4 Mac minis on sale for $50-$80 off MSRP at...
B&H Photo has M4 Mac minis in stock and on sale right now for $50 to $80 off Apple’s MSRP, each including free 1-2 day shipping to most US addresses: – M4 Mac mini (16GB/256GB): $549, $50 off... Read more
Buy an iPhone 16 at Boost Mobile and get one...
Boost Mobile, an MVNO using AT&T and T-Mobile’s networks, is offering one year of free Unlimited service with the purchase of any iPhone 16. Purchase the iPhone at standard MSRP, and then choose... Read more
Get an iPhone 15 for only $299 at Boost Mobil...
Boost Mobile, an MVNO using AT&T and T-Mobile’s networks, is offering the 128GB iPhone 15 for $299.99 including service with their Unlimited Premium plan (50GB of premium data, $60/month), or $20... Read more
Unreal Mobile is offering $100 off any new iP...
Unreal Mobile, an MVNO using AT&T and T-Mobile’s networks, is offering a $100 discount on any new iPhone with service. This includes new iPhone 16 models as well as iPhone 15, 14, 13, and SE... Read more
Apple drops prices on clearance iPhone 14 mod...
With today’s introduction of the new iPhone 16e, Apple has discontinued the iPhone 14, 14 Pro, and SE. In response, Apple has dropped prices on unlocked, Certified Refurbished, iPhone 14 models to a... Read more
B&H has 16-inch M4 Max MacBook Pros on sa...
B&H Photo is offering a $360-$410 discount on new 16-inch MacBook Pros with M4 Max CPUs right now. B&H offers free 1-2 day shipping to most US addresses: – 16″ M4 Max MacBook Pro (36GB/1TB/... Read more
Amazon is offering a $100 discount on the M4...
Amazon has the M4 Pro Mac mini discounted $100 off MSRP right now. Shipping is free. Their price is the lowest currently available for this popular mini: – Mac mini M4 Pro (24GB/512GB): $1299, $100... Read more
B&H continues to offer $150-$220 discount...
B&H Photo has 14-inch M4 MacBook Pros on sale for $150-$220 off MSRP. B&H offers free 1-2 day shipping to most US addresses: – 14″ M4 MacBook Pro (16GB/512GB): $1449, $150 off MSRP – 14″ M4... Read more

Jobs Board

All contents are Copyright 1984-2011 by Xplain Corporation. All rights reserved. Theme designed by Icreon.