Self-enforcing protocols instead of mere promises
Summary
Bruce Schneier examines protocols whose technical structure enforces agreed rules and reduces trust in individual participants. The text deals with cryptography and game-theoretic incentives. Fair exchange protocols are a classic security problem.
Ideas
- Cryptography can technically limit permitted actions.
- Fair exchange protocols prevent one-sided advantage when transactions are aborted.
- Digital signatures make origin and integrity verifiable.
- Distributed decisions avoid a single all-powerful intermediary.
- Incentives complement technical rules where complete enforcement remains impossible.
- Protocol assumptions must explicitly account for malicious participants.
Insights
- Good protocols replace trust with verifiable limits, not with hope.
- Technical enforcement can stabilise undesirable rules just as effectively.
- Security properties only hold within the stated attacker model.
- Social conflicts do not disappear when software automates individual steps.
Facts
- Digital signatures do not prove that the signed content is true.
Recommendations
- Document participants, capabilities and assumed attacks.
- Avoid central privileges without verifiable oversight.
- Also test protocols under abort, replay and contradictory messages.
References
Links to the original source and the Web Archive open in a new tab.