On 15 Mar 2011, at 6:44 AM, Rainer Hörbe wrote:
> Technical and legal trust maps are not congruent because the actors are different. Eg. a Relying Party has trust to a subject's identity, whereas the verifier (the RP's agent to execute the authN protocol) has a technical trust to the claimant (the technical agent executing the authN protocol on behalf of the subject). I suggest to put them into separate diagrams.

I agree (scenario diagrams are yet a third layer, in a way, since they express wishes/user stories/end goals rather than implementation details!). We have tried to do a careful job of distinguishing and then linking these sets of actors in the current trust model document. Hopefully this will serve us well in the diagram and doc revisions.


