SSL seems to conflate 2 ideas, proof of identity and an encryption layer. Would it be possible to have the encryption layer without requiring a third party to handle keys?
These ideas are inextricably linked! If you cannot verify the identity of the other end, you cannot verify that a man in the middle is decrypting, monitoring or altering, and then passing the data on to the real endpoint.