首页> 外文会议>International Conference on Pervasive Computing >TOWARDS A NEXT-GENERATION TRUST MANAGEMENT INFRASTRUCTURE FOR OPEN COMPUTING SYSTEMS
【24h】

TOWARDS A NEXT-GENERATION TRUST MANAGEMENT INFRASTRUCTURE FOR OPEN COMPUTING SYSTEMS

机译:迈向开放计算系统的下一代信任管理基础架构

获取原文

摘要

Basically, there are two intertwined kinds of security mechanisms: monitoring including access control and cryptographic protocols. The purpose of an access control system is to enforce security policies by gating access to, and execution of, processes and services within a computing system. Specification and enforcement of permissions can be based on asymmetric cryptography. In order to employ asymmetric cryptography in open computing environments we need appropriate trust management infrastructures that enable entities to establish mutual trust. Management of trust is organized within a public key infrastructure, PKI for short. Credentials assert a binding between a principal, represented by a public key, and some property. Current proposals investigating the definition of PKI and the application of credential-based access control treat existing PKI models (e.g. X.509) and trust management approaches (e.g. SPKI/SDSI) as competing technologies. We take a different position. We argue here that a trust management infrastructure for open computing environments has to use and to link existing approaches. We explain which requirements a next-generation trust management approach has to fulfill. After presenting an application scenario, we finally outline the design of a next-generation trust management approach that we believe really would appear to be worthwhile for a broad spectrum of applications.
机译:基本上,有两个交织在线的安全机制:监控包括访问控制和加密协议。访问控制系统的目的是通过在计算系统内的访问和执行,进程和服务的访问和执行来强制执行安全策略。权限的规范和实施可以基于非对称密码术。为了在开放计算环境中使用非对称密码,我们需要适当的信任管理基础架构,使实体能够建立相互信任。信托的管理是在公共关键基础设施中举办的,PKI短暂。凭据在公钥和一些属性代表的主体之间断言绑定。当前提案调查PKI的定义和凭证的访问控制处理现有的PKI模型(例如X.509)和信任管理方法(例如SPKI / SDSI)作为竞争技术。我们采取不同的立场。我们在此辩称,用于开放计算环境的信任管理基础架构必须使用并链接现有方法。我们解释了下一代信托管理方法必须履行的要求。在提出申请方案之后,我们终于概述了一个下一代信任管理方法的设计,我们认为我们认为对广泛的应用程序似乎是值得的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号