Skip to main content

Dentists, blockchains, novocain

 Xxx novocain xxx

Let’s begin by recapitulating the elements of the problem space. If I show up at the local practice in response to their dentist wanted ad on indeed.com there are three domains to consider. In the authorisation domain, I must present the appropriate qualification and the practice must be able to validate it. Of course, I must be able to demonstrate in the authentication domain that the qualification belongs to me. And although it is not at all necessary for the regular functioning of the practice, the identification domain must provide my “real” identity because of the rules of the medical world.

Let’s walk through these steps.

First, presenting the qualification.

Second, authenticating the qualification.

 

Third, linking the qualification to identity.

Comments

Popular posts from this blog

We could fix mobile security, you know. We don't, but we could

Earlier in the week I blogged about mobile banking security , and I said that in design terms it is best to assume that the internet is in the hands of your enemies. In case you think I was exaggerating… The thieves also provided “free” wireless connections in public places to secretly mine users’ personal information. From Gone in minutes: Chinese cybertheft gangs mine smartphones for bank card data | South China Morning Post Personally, I always use an SSL VPN when connected by wifi (even at home!) but I doubt that most people would ever go to this trouble or take the time to configure a VPN and such like. Anyway, the point is that the internet isn’t secure. And actually SMS isn’t much better, which is why it shouldn’t really be used for securing anything as important as home banking. The report also described how gangs stole mobile security codes – which banks automatically send to card holders’ registered mobile phones to verify online transactions – by using either a Trojan...