Snowflake project (1998-2000)

In the Snowflake project, we tackled the problem of naming and sharing resources across administrative boundaries. We developed a theory and implementation for restricted delegation, building on the classic "speaks-for" relation that forms the foundation of many authorization logics. In Snowflake, principals can delegate authority to other principles, but in a limited way; in earlier work, it was only possible for a principal to delegate all of its authority. The work is theoretically well-founded and yet practical to implement.

This work is most completely described in Howell's dissertation [howell:thesis]; the single most central paper is [howell:end-to-end].


Jon Howell and David Kotz.

Funding and acknowledgements

