<HTML>
<HEAD>
   <META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
   <META NAME="Author" CONTENT="Mark S. Miller">
   <META NAME="GENERATOR" CONTENT="Mozilla/4.01 [en] (Win95; I) [Netscape]">
   <TITLE>Confusing the Deputy</TITLE>
</HEAD>
<BODY BACKGROUND="wood.gif">

<CENTER>
<H1>
The Confused Deputy, 13 years later</H1></CENTER>
&lt;&lt;<A HREF="confinement.html">Confinement</A>&lt;&lt; Up to <A HREF="leakage.html">Leakage</A>
>><A HREF="conspirators.html">Communicating Conspirators</A>>>
<CENTER><IMG SRC="deputy.gif" HEIGHT=380 WIDTH=561></CENTER>


<P>Bob has the Power, and Bob and Mallet are properly communicating.&nbsp;
Bob wishes to hold the power and use it properly.&nbsp; However, he wishes
to deny the power to Mallet, and Alice trusts him to do so successfully.&nbsp;
Alice considers Bob her deputy in the use of this Power.&nbsp; Can Mallet
confuse him into providing the power to Mallet?

<P>See <A HREF="http://www.cis.upenn.edu/~KeyKOS/ConfusedDeputy.html">the
original paper</A>. Netscape calls this problem a "<A HREF="http://developer.netscape.com/library/documentation/security/sectn1.html#W-HAT-DO-YOU-MEAN-BY-A-(L-URING)-ATTACK">Luring
Attack</A>".
</BODY>
</HTML>
