首页> 外文会议>International conference on security standardisation research >A Practical Trust Framework: Assurance Levels Repackaged Through Analysis of Business Scenarios and Related Risks
【24h】

A Practical Trust Framework: Assurance Levels Repackaged Through Analysis of Business Scenarios and Related Risks

机译:一个实用的信任框架:通过分析业务场景和相关风险来重新包装保证水平

获取原文

摘要

In cyberspace, standards for the expression of the trustworthiness of identities have been developed by various parties. This trustworthiness is often referred to as entity authentication assurance, and its degree is often called LoA (levels of assurance, or assurance levels). There are two prominent LoA standards: NIST SP800-63-2 and ISO/IEC 29115:2013. LoAs are designed to express different levels of assurance. Multiple viewpoints are set in assessment, and related assessment criteria for each viewpoint are packaged into one LoA. For deployment of LoAs in enterprise business scenarios, the choice of assessment criteria in a given LoA must match the specific business requirements. We perform a field survey on business scenarios in which trust in identities is a major problem. In the survey, we focus on two key factors of assessment: identity proofing and authentication process. In addition, we observe the overall fit and gap in business scenarios. Results indicate that raising the assurance of the authentication process is effective for raising the overall assurance level. Based on the investigations performed, we repackage light weight identity proofing and LoA 2 equivalent credential management and usage into a new assurance level, LoA 1+, for the "right" cost benefit balance.
机译:在网络空间中,各方制定了表达身份可信度的标准。这种可信度通常被称为实体认证保证,其程度通常被称为LOA(保证或保证水平的水平)。有两个突出的LOA标准:NIST SP800-63-2和ISO / IEC 29115:2013。 LOAS旨在表达不同程度的保证。在评估中设置多个视点,每个视点的相关评估标准包装为一个LOA。为了在企业业务场景中部署LOAS,给定LOA中的评估标准的选择必须与特定的业务需求相匹配。我们对企业方案进行了现场调查,其中信任身份是一个主要问题。在调查中,我们专注于评估的两个关键因素:身份证明和认证过程。此外,我们遵守业务场景的整体契合和差距。结果表明,提高认证过程的保证对于提高整体保证水平是有效的。根据进行的调查,我们将重量级身份证明和LOA 2等效凭证管理和用途重新打包到新的保证水平LoA 1+,以获得“正确的”成本效益平衡。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号