首页> 外文会议>17th ACM conference on computer and communications security 2010 >Survivable Key Compromise in Software Update Systems
【24h】

Survivable Key Compromise in Software Update Systems

机译:软件更新系统中的生存键破坏

获取原文
获取原文并翻译 | 示例

摘要

Today's software update systems have little or no defense against key compromise. As a result, key compromises have put millions of software update clients at risk. Here we identify three classes of information whose authenticity and integrity are critical for secure software updates. Analyzing existing software update systems with our framework, we find their ability to communicate this information securely in the event of a key compromise to be weak or nonexistent. We also find that the security problems in current software update systems are compounded by inadequate trust revocation mechanisms. We identify core security principles that allow software update systems to survive key compromise. Using these ideas, we design and implement TUF, a software update framework that increases resilience to key compromise.
机译:当今的软件更新系统几乎无法防御关键的妥协。结果,关键的妥协使数百万的软件更新客户端面临风险。在这里,我们确定了三类信息,其真实性和完整性对​​于安全软件更新至关重要。通过使用我们的框架分析现有的软件更新系统,我们发现在关键的折衷方案存在漏洞或不存在的情况下,它们能够安全地传达此信息。我们还发现,当前的软件更新系统中的安全性问题由于信任撤销机制不足而变得更加复杂。我们确定了允许软件更新系统幸免于关键妥协的核心安全原则。利用这些想法,我们设计并实现了TUF,这是一种软件更新框架,可以提高对关键妥协的适应性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号