Michael D. Schroeder
- Co-authored The Protection of Information in Computer Systems (1975) with Jerome Saltzer
- Co-authored Using Encryption for Authentication in Large Networks of Computers (1978) with Roger Needham
- The symmetric-key protocol from that paper is the basis of Kerberos
Bio
Michael D. Schroeder co-authored two of the foundational papers in this field within three years of each other: the 1975 design-principles paper with Jerome Saltzer at MIT, and the 1978 authentication paper with Roger Needham at Xerox PARC.
Profile built from public academic and publication records.
Where their work shows up
The 1978 paper's symmetric-key protocol is the direct ancestor of Kerberos, which means it is the ancestor of how Windows domains authenticate to this day. Its public-key variant was later shown to be flawed and fixed, which established something equally important: authentication protocols need formal analysis, not just careful reading. That lesson runs straight through to the formal work on OAuth decades later. See Kerberoasting and Kerberos delegation abuse for what the protocol's descendants look like under attack.
Related on Start with Identity
- ExpertCo-author of the NIST RBAC model
David Ferraiolo co-authored "Role-Based Access Controls" with Rick Kuhn, presented at the 15th National Computer Security Conference in October 1992. The NIST m
- ExpertCo-author of the NIST RBAC model
Rick Kuhn co-authored the 1992 NIST paper on role-based access control with David Ferraiolo and has worked on the model, its formalization, and its assurance ev
- ExpertDirector, CyLab; Professor, Carnegie Mellon University
Lorrie Faith Cranor directs CyLab at Carnegie Mellon and the CyLab Usable Privacy and Security Laboratory, founded the SOUPS symposium, and co-edited Security a