首页
外语
计算机
考研
公务员
职业资格
财经
工程
司法
医学
专升本
自考
实用职业技能
登录
计算机
Trust is typically interpreted as a subjective belief in the reliability,honesty and security of an entity on which we depend (
Trust is typically interpreted as a subjective belief in the reliability,honesty and security of an entity on which we depend (
admin
2020-04-30
13
问题
Trust is typically interpreted as a subjective belief in the reliability,honesty and security of an entity on which we depend (71)________________ our welfare.In online environments we depend on a wide spectrum of things,ranging from computer hardware,software and data to people and organizations.A security solution always assumes certain entities function according to specific policies.To trust is precisely to make this sort of assumptions,hence,a trusted entity is the same as an entity that is assumed to function according to policy. A consequence of this is that a trusted component of a system must work correctly in order for the security of that system to hold,meaning that when a trusted (72)________________ fails,then the systems and applications that depend on it can (73)________________ be considered secure.An often cited articulation of this principle is:‘a trusted system or component is one that can break your security policy’(which happens when the trusted system fails).The same applies to a trusted party such as a service provider(SP for short),that is,it must operate according to the agreed or assumed policy in order to ensure the expected level of security and quality of services.A paradoxical conclusion to be drawn from this analysis is that security assurance may decrease when increasing the number of trusted components and parties that a service infrastructure depends on.This is because the security of an infrastructure consisting of many trusted components typically follows the principle of the weakest link,that is,in many situations the overall security can only be as strong as the least reliable or least secure of al l the trusted components.We cannot avoid using trusted security components,but the fewer the better.This is important to understand when designing the identity management architectures,that is,fewer the trusted parties in an identity management model,stronger the security that can be achieved by it.
The transfer of the social constructs of identity and trust into digital alld computational conceptshelpsindesigningandimplementinglarge scaleonlinemarketsandcommunities,and also plays an important role in the converging mobile and Internet environments.Identity management fdenoted IdM hereafter)is about recognizing and verifying the correctness of identities in online environments.Trust management becomes a component of (74)________________ whenever different parties rely on each other for identity provision and authentication.IdM and trust management therefore depend on each other in complex ways because the correctness of the identity itself must be trusted for the quality and reliability of the corresponding entity to be trusted.IdM is also an essential concept when defining authorisation policies in personalised services.
Establishing trust always has a cost,so that having complex trust requirements typically leads to high overhead in establishing the required trust.To reduce costs there will be incentives for stakeholders to‘cut comers’regarding trust requirements,which could lead to inadequate security.The challenge is tO design IdM systems with relatively simple trust requirements.Cryptographic mechanisms are often a core component of IdM solutions,for example,for entity and data authentication.With cryptography,it is often possible to propagate trust from where it initially exists to where it is needed.The establishment of initial (75)________________ usually takes place in the physical world,and the subsequent propagation of trust happens online,often in an automated manner.
选项
A、entity
B、person
C、component
D、thing
答案
C
解析
转载请注明原文地址:https://kaotiyun.com/show/kMTZ777K
本试题收录于:
信息安全工程师上午基础知识考试题库软考中级分类
0
信息安全工程师上午基础知识考试
软考中级
相关试题推荐
(2012上项管)机会研究、初步可行性研究、详细可行性研究、评估与决策是项目前期的四个阶段,在实际工作中,依据项目的规模和繁简程度,其中可以省略的阶段是______。
(2005下项管)某项目的项目范围已经发生变更,因此成本基线也将发生变更,项目经理需要尽快______。
(2013上项管)某单位新近一批600台不同型号的PC机,均由同一设备生产厂家提供。按照质量管理相关规定,以下质检方法中,正确的是______。
(2009上项管)关于活动资源估算正确的叙述是______。
(2010下项管)管理信息系统规划的方法有很多,最常使用的方法有三种:关键成功因素法(CriticalSuccessFactors,CSF),战略目标集转化法(StrategySetTransformation,SST)和企业系统规划法(Busin
(2009上网工)两个公司希望通过Internet传输大量敏感数据,从信息源到目的地之间的传输数据以密文形式出现,而且不希望由于在传输结点使用特殊的安全单元而增加开支,最合适的加密方式是______(1),使用会话密钥算法效率最高的是______(2)。
(2009上项管)螺旋模型是一种演进式的软件过程模型,结合了原型开发方法的系统性和瀑布模型可控性特点。它有两个显著特点,一是采用______(1)的方式逐步加深系统定义和实现的深度,降低风险;二是确定一系列______(2),确保项目开发过程中的相关利益者
(2010下项管)下图是某架构在J2EE平台上设计的一个信息系统集成方案架构图,图中的(1)、(2)和(3)分别表示______。
区块链是一种按照时间顺序将数据区块以顺序相连的方式组合成的一种链式数据结构,并以密码学方式保证的不可篡改和不可伪造的分布式账本。主要解决交易的信任和安全问题,最初是作为______的底层技术出现的。
随机试题
膈的主动脉裂孔位置在()
一女性患者,肥胖、痤疮、紫纹,化验血皮质醇增高,血糖增高,小剂量地塞米松抑制试验血皮质醇较对照组低38%,大剂量地塞米松抑制试验血皮质醇较对照组低78%。该患者最可能的诊断是
对境外申请人在中国进行国际多中心药物临床试验的规定有()。
当合同履行过程中发现,对给付货币的地点,合同中没有明确约定,事后双方又未能达成补充协议,根据《合同法》,应在( )履行。
软土隧道通常修建在( )地下。
某7层病房大楼,建筑高度27m,每层划分2个防火分区,走道两侧双面布房,每层设计容纳人数为110人。下列对该病房大楼安全疏散设施的防火检查结果中,不符合现行国家标准要求的是()。
会计资料的真实性、完整性,是会计资料最基本的质量要求。()
党在社会主义初级阶段的基本纲领规定,建设有中国特色社会主义政治的基本目标是()。
Fordecades,postersdepictingrabbitswithinflamed,reddenedeyessymbolizedcampaignsagainstthetestingofcosmeticsonani
Althoughfearofmathisnotapurelyfemalephenomenon,girlstendtodropoutmathsoonerthanboys,andadultwomenexperienc
最新回复
(
0
)