boltlabs-inc / key-mgmt-spec

Formal specification for the key management project
MIT License
3 stars 2 forks source link

Specify integrated authentication and user onboarding protocols #59

Open indomitableSwan opened 2 years ago

indomitableSwan commented 2 years ago

Since Lock Keeper does not provide a stand-alone, user-facing application, we want to provide a flexible way for Service Providers to authenticate their users that does not negatively impact security of Lock Keeper functionalities or the user experience.

To that end, we need a technical specification of a system that:

We currently have an internal draft that treats the case of a user who has not previously registered for an account with the Service Provider. A starting point for completion of this epic is translation of this high-level draft to a detailed technical specification.

jakinyele commented 2 years ago

@indomitableSwan For my own clarification, will there be a separate epic for an integrated authentication plan for the remote-client or is that implied by this epic?

indomitableSwan commented 2 years ago

@indomitableSwan For my own clarification, will there be a separate epic for an integrated authentication plan for the remote-client or is that implied by this epic?

This is not applicable for the remote client.