首页> 外文会议>International Conference on Cloud Security Management >Forensic Readiness for Cloud-Based Distributed Workflows
【24h】

Forensic Readiness for Cloud-Based Distributed Workflows

机译:基于云的分布式工作流的法医准备

获取原文
获取外文期刊封面目录资料

摘要

Distributed workflows in the physical world can be documented by so-called process slips, where each action in the process is assigned to the responsible person and progress or completion of sub-tasks are confirmed using signatures on the process slip. The paper version creates a paper-based audit trail that documents who has done which part of the process and when. In the digital world, electronic process slips have been proposed that use digital signatures to achieve a similar behaviour in distributed service-based processes. This also provides a trail of linked digital signatures to represent the process. When moving such distributed workflows to the cloud (at least partly), steps might be fully automatic or only initiated by the user without any clear control on the execution of the process. Therefore, documenting the user interaction is not sufficient. This paper proposes to extend the idea of electronic process slips by hardware-based security to control the cloud server and to securely document the execution of particular steps in the process. The concept is based on Trusted Platform Modules (TPM) as specified by the Trusted Computing Group (TCG).The result is an electronic audit trail that provides reliable and secure information on the execution of the electronic process that ensures the satisfaction of specific requirements for forensic readiness in distributed workflows including cloud-based services. The composition concept remains as powerful as in the original version of the electronic process slip.
机译:物理世界中的分布式工作流程可以通过所谓的进程单据记录,其中该过程中的每个操作被分配给负责人,并且使用过程滑动上的签名确认了子任务的进度或完成。纸张版本创建了一种基于纸张的审计跟踪,该审计跟踪已完成该过程的哪个部分以及何时。在数字世界中,已经提出了电子处理单,其使用数字签名来实现基于服务的过程中的类似行为。这也提供了链接数字签名的跟踪来表示该过程。当将这种分布式工作流移动到云(至少部分)时,步骤可能是完全自动的或仅由用户发起,而不会对该过程执行的任何清晰控制。因此,记录用户交互是不够的。本文提出通过基于硬件的安全性来控制电子过程的思想来控制云服务器,并安全地记录过程中的特定步骤。该概念基于受信任计算组(TCG)指定的可信平台模块(TPM)。结果是一种电子审计跟踪,可提供有关执行电子过程的可靠和安全信息,确保对特定要求的满意度分布式工作流中的法医拟计包括基于云的服务。组成概念与电子工艺单据的原始版本一样强大。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号