3 ms·
If your data is so sensitive that you do not want to store it on a central server then why not consider the PGP approach? User 2 sends a request to user 1 (who
by bdfh42 13y ago
If your data is so sensitive that you do not want to store it on a central server then why not consider the PGP approach?
User 2 sends a request to user 1 (who has the data) sending his or her public key and asking for the data encrypted using the public key. User 2 then decrypts the message using his private key and makes his own local copy.
How do you communicate data changes between data holders - a version control problem perhaps?
- chany2 13y ago^ One researcher recommended similar approach, the data stored centrally, and give other users access keys as the means of granting them permission to read those data. However the issue here, don't I end up 'storing' that access key as well? Unless its a password-type, where user have to remember and manually enter it every time... He also suggest taking a push model (the central storage) rather than pull model (device storage). I am still debating, and researching. Any other thoughts?
- bdfh42 13y agoIf you read up on the PGP idea you will see that storing people's public keys is not an issue - they may be broadcast to the world. The clever bit is that they are combined with a private key (that you do not store or exchange) to encrypt and ultimately decrypt any given message or data.