Abstract
We propose a new distributed security infrastucture, called SDSI (pronounced "Sudsy").
SDSI combines a simple public-key infrastructure design with a means of defining groups
and issuing group-membership certificates. SDSI's groups provides simple, clear
terminology for defining access-control lists and security policies. SDSI's design
emphasizes linked local name spaces rather than a hierarchical global name space.