首页> 外文会议>5th ACM workshop on scalable trusted computing 2010 >System Security, Platform Security and Usability
【24h】

System Security, Platform Security and Usability

机译:系统安全性,平台安全性和可用性

获取原文
获取原文并翻译 | 示例

摘要

Scalable trusted computing seeks to apply and extend the fundamental technologies of trusted computing to large-scale systems. To provide the functionality demanded by users, bootstrapping a trusted platform is but the first of many steps in a complex, evolving mesh of components. The bigger picture involves building up many additional layers to allow computing and communication across large-scale systems, while delivering a system retaining some hint of the original trust goal. Not to be lost in the shuffle is the most important element: the system's human users. Unlike 40 years ago, they cannot all be assumed to be computer experts, under the employ of government agencies which provide rigorous and regular training, always on tightly controlled hardware and software platforms. It seems obvious that the design of scalable trusted computing systems necessarily must involve, as an immutable design constraint, realistic expectations of the actions and capabilities of normal human users. Experience shows otherwise. The security community does not have a strong track record of learning from user studies, nor of acknowledging that it is generally impossible to predict the actions of ordinary users other than by observing (e.g., through user experience studies) the actions such users actually take in the precise target conditions. We assert that because the design of scalable trusted computing systems spans the full spectrum from hardware to software to human users, experts in all these areas are essential to the end-goal of scalable trusted computing.
机译:可扩展的可信计算旨在将可信计算的基本技术应用并扩展到大规模系统。为了提供用户所需的功能,引导受信任的平台只是复杂,不断发展的组件网格中许多步骤的第一步。更大的前景包括建立许多其他层,以允许跨大型系统进行计算和通信,同时提供保留原始信任目标的某些提示的系统。最重要的要素是:不被洗牌所迷惑:系统的人类用户。与40年前不同,在政府机构的雇用下,不能总是假设他们都是计算机专家,而政府机构总是在严格控制的硬件和软件平台上提供严格和定期的培训。显而易见,可扩展的可信计算系统的设计必须必然包含对普通人类用户的行为和功能的现实期望,作为不变的设计约束。经验表明情况并非如此。安全社区没有从用户研究中学习的良好记录,也没有承认除了观察(例如,通过用户体验研究)用户通常采取的行动外,通常不可能预测普通用户的行动。精确的目标条件。我们认为,由于可扩展可信计算系统的设计涵盖了从硬件到软件再到人类用户的整个范围,因此所有这些领域的专家对于可扩展可信计算的最终目标都是必不可少的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号