首页
外语
计算机
考研
公务员
职业资格
财经
工程
司法
医学
专升本
自考
实用职业技能
登录
计算机
Trust is typically interpreted as a subjective belief in the reliability,honesty and security of an entity on which we depend (
Trust is typically interpreted as a subjective belief in the reliability,honesty and security of an entity on which we depend (
admin
2020-04-30
42
问题
Trust is typically interpreted as a subjective belief in the reliability,honesty and security of an entity on which we depend (71)________________ our welfare.In online environments we depend on a wide spectrum of things,ranging from computer hardware,software and data to people and organizations.A security solution always assumes certain entities function according to specific policies.To trust is precisely to make this sort of assumptions,hence,a trusted entity is the same as an entity that is assumed to function according to policy. A consequence of this is that a trusted component of a system must work correctly in order for the security of that system to hold,meaning that when a trusted (72)________________ fails,then the systems and applications that depend on it can (73)________________ be considered secure.An often cited articulation of this principle is:‘a trusted system or component is one that can break your security policy’(which happens when the trusted system fails).The same applies to a trusted party such as a service provider(SP for short),that is,it must operate according to the agreed or assumed policy in order to ensure the expected level of security and quality of services.A paradoxical conclusion to be drawn from this analysis is that security assurance may decrease when increasing the number of trusted components and parties that a service infrastructure depends on.This is because the security of an infrastructure consisting of many trusted components typically follows the principle of the weakest link,that is,in many situations the overall security can only be as strong as the least reliable or least secure of al l the trusted components.We cannot avoid using trusted security components,but the fewer the better.This is important to understand when designing the identity management architectures,that is,fewer the trusted parties in an identity management model,stronger the security that can be achieved by it.
The transfer of the social constructs of identity and trust into digital alld computational conceptshelpsindesigningandimplementinglarge scaleonlinemarketsandcommunities,and also plays an important role in the converging mobile and Internet environments.Identity management fdenoted IdM hereafter)is about recognizing and verifying the correctness of identities in online environments.Trust management becomes a component of (74)________________ whenever different parties rely on each other for identity provision and authentication.IdM and trust management therefore depend on each other in complex ways because the correctness of the identity itself must be trusted for the quality and reliability of the corresponding entity to be trusted.IdM is also an essential concept when defining authorisation policies in personalised services.
Establishing trust always has a cost,so that having complex trust requirements typically leads to high overhead in establishing the required trust.To reduce costs there will be incentives for stakeholders to‘cut comers’regarding trust requirements,which could lead to inadequate security.The challenge is tO design IdM systems with relatively simple trust requirements.Cryptographic mechanisms are often a core component of IdM solutions,for example,for entity and data authentication.With cryptography,it is often possible to propagate trust from where it initially exists to where it is needed.The establishment of initial (75)________________ usually takes place in the physical world,and the subsequent propagation of trust happens online,often in an automated manner.
选项
A、SP
B、IdM
C、Internet
D、entity
答案
B
解析
转载请注明原文地址:https://kaotiyun.com/show/3MTZ777K
本试题收录于:
信息安全工程师上午基础知识考试题库软考中级分类
0
信息安全工程师上午基础知识考试
软考中级
相关试题推荐
(2014下集管)______不属于电子商务基础设施。
(2010下集管)某体育设备厂商已经建立覆盖全国的分销体系。为进一步拓展产品销售渠道,压缩销售各环节的成本,拟建立电子商务网站接受体育爱好者的直接订单。这种电子商务属于______模式。
(2009下架构)软件架构贯穿于软件的整个生命周期,但在不同阶段对软件架构的关注力度并不相同,在______阶段,对软件架构的关注最多。
(2010下集管)某公司最近承接了一个大型信息系统项目,项目整体压力较大,对这个项目中的变更,可以使用______等方式提高效率。①分优先级处理;②规范处理;③整批处理;④分批处理
(2013上项管)分析成本构成结果,找出各种可以相互替代的成本,协调各种成本之间的关系属于______的内容。
(2011上项管)根据如下图某项目的网络图,在最佳的人力资源利用情况下,限定在最短时间内完成项目,则项目的人力资源要求至少为______人。
(2009上项管)某项目的时标网络图如下(时间单位:周),在项目实施过程中,因负责实施的工程师误操作发生了质量事故,需整顿返工,造成工作④-⑥拖延3周,受此影响,工程的总工期会拖延______周。
(2009上软评)下面关于加密的说法中,错误的是______。
(2007下软设)某Web网站向CA申请了数字证书。用户登录该网站时,通过验证______(1),可确认该数字证书的有效性,从而______(2)。(1)
(2007上网工)采用Kerberos系统进行认证时,可以在报文中加入______来防止重放攻击。
随机试题
以下适用于了解带有个人性和隐私性问题的访谈法是()
费尔巴哈哲学的出发点是()
Inthelate1860’s,industryinAmericagrewrapidly.Morefactoriesmeantmorejobs.Butworkingconditionsweredangerous.Emp
女,37岁,上腹部胀痛不适,B超发现肝内占位。还应该做哪些检查
突出体现医德情感作用的是突出体现医德义务作用的是
关于微孔滤膜特点的说法,正确的有()。
在广告创意过程的资料分析阶段,应完成()等任务。
初级群体指的是由面对面互动所形成的、具有亲密的人际关系和浓厚的感情色彩的社会群体;次级群体指的是其成员为了某种特定的目标集合在一起,通过明确的规章制度结成正规关系的社会群体。根据上述定义,下列涉及次级群体的是:
主张课程的组织应该考虑到儿童心理发展的次序的是
A、Helockedhissuitathome.B、Hecouldn’tpayfordry-cleaning.C、Hehadnotimetofetchhissuit.D、Hedidn’tdry-cleanhis
最新回复
(
0
)