We present a security architecture for access control in ad-hoc networks of mobile electronic devices. Ad-hoc networks are
formed on demand without support from pre-existing infrastructure such as central servers, security associations or CAs. Our
architecture is fully distributed and based on groups and public-key certification. The goal is a survivable system that functions
well even when network nodes fail and connections are only occasional. We identify some open problems in the optimal use of
unreliable communications for security management.