首页
外语
计算机
考研
公务员
职业资格
财经
工程
司法
医学
专升本
自考
实用职业技能
登录
计算机
Trust is typically interpreted as a subjective belief in the reliability,honesty and security of an entity on which we depend (
Trust is typically interpreted as a subjective belief in the reliability,honesty and security of an entity on which we depend (
admin
2020-04-30
9
问题
Trust is typically interpreted as a subjective belief in the reliability,honesty and security of an entity on which we depend (71)________________ our welfare.In online environments we depend on a wide spectrum of things,ranging from computer hardware,software and data to people and organizations.A security solution always assumes certain entities function according to specific policies.To trust is precisely to make this sort of assumptions,hence,a trusted entity is the same as an entity that is assumed to function according to policy. A consequence of this is that a trusted component of a system must work correctly in order for the security of that system to hold,meaning that when a trusted (72)________________ fails,then the systems and applications that depend on it can (73)________________ be considered secure.An often cited articulation of this principle is:‘a trusted system or component is one that can break your security policy’(which happens when the trusted system fails).The same applies to a trusted party such as a service provider(SP for short),that is,it must operate according to the agreed or assumed policy in order to ensure the expected level of security and quality of services.A paradoxical conclusion to be drawn from this analysis is that security assurance may decrease when increasing the number of trusted components and parties that a service infrastructure depends on.This is because the security of an infrastructure consisting of many trusted components typically follows the principle of the weakest link,that is,in many situations the overall security can only be as strong as the least reliable or least secure of al l the trusted components.We cannot avoid using trusted security components,but the fewer the better.This is important to understand when designing the identity management architectures,that is,fewer the trusted parties in an identity management model,stronger the security that can be achieved by it.
The transfer of the social constructs of identity and trust into digital alld computational conceptshelpsindesigningandimplementinglarge scaleonlinemarketsandcommunities,and also plays an important role in the converging mobile and Internet environments.Identity management fdenoted IdM hereafter)is about recognizing and verifying the correctness of identities in online environments.Trust management becomes a component of (74)________________ whenever different parties rely on each other for identity provision and authentication.IdM and trust management therefore depend on each other in complex ways because the correctness of the identity itself must be trusted for the quality and reliability of the corresponding entity to be trusted.IdM is also an essential concept when defining authorisation policies in personalised services.
Establishing trust always has a cost,so that having complex trust requirements typically leads to high overhead in establishing the required trust.To reduce costs there will be incentives for stakeholders to‘cut comers’regarding trust requirements,which could lead to inadequate security.The challenge is tO design IdM systems with relatively simple trust requirements.Cryptographic mechanisms are often a core component of IdM solutions,for example,for entity and data authentication.With cryptography,it is often possible to propagate trust from where it initially exists to where it is needed.The establishment of initial (75)________________ usually takes place in the physical world,and the subsequent propagation of trust happens online,often in an automated manner.
选项
A、SP
B、IdM
C、Internet
D、entity
答案
B
解析
转载请注明原文地址:https://kaotiyun.com/show/3MTZ777K
本试题收录于:
信息安全工程师上午基础知识考试题库软考中级分类
0
信息安全工程师上午基础知识考试
软考中级
相关试题推荐
(2013上集管)项目论证是对拟实现项目技术上的先进性,适用性,经济的合理性,实施上的可能性,风险控制等进行全面的综合分析,为项目决策提供客观依据的一种技术经济研究活动,其中______不属于项目论证的主要内容。
(2009下架构)软件架构需求是指用户对目标软件系统在功能、行为、性能、设计约束等方面的期望。以下活动中,不属于软件架构需求过程范畴的是______。
(2011上集管)某项目经理在进行成本估算时采用______方法,制定出如下的人力资源成本估算表。
(2007上网工)下图为某系统集成项目的网络工程计划图,从图可知项目最短工期为____(1)天,至少需要投入_____(2)人才能完成该项目(假设每个技术人员均能胜任每项工作)。(2)
(2012上项管)配置管理中有一项工作是变更控制,其中配置状态的过程如下图所示:在这个状态变化过程中,图中的(1)、(2)、(3)三个状态依次为______。
(2005下项管)在下列网络服务中,_______(1)是远程登录服务,Internet中域名与IP地址之间的翻译是由______(2)来完成的。(1)
(2005上软评)V模型指出,_______(1)对程序设计进行验证,______(2)对系统设计进行验证,_____(3)应当追溯到用户需求说明。(1)
(2007下项管)CMMI提供了两种模型表述方式:“连续式”和“阶段式”。以下说法中正确的是______。
Typically, these are concern with the establishment of(66)the network and with the control of the flow of messages across this
a=17,b=2,则满足a与b取模同余的是(69)________________。
随机试题
具有羧酸酯结构的麻醉药是
甲乙丙三国因历史原因,冲突不断,甲国单方面暂时关闭了驻乙国使馆。艾诺是甲国派驻丙国使馆的二秘,近日被丙国宣布为不受欢迎的人。根据相关国际法规则,下列哪些选项是正确的?(2014年卷一第74题)
不同的职能部门对于风险状况的需求是不一样的,风险管理委员会需要的是()。
下列古词作者是“唐宋八大家”之一的是()。
信息技术一般控制通常不包括的是()。
巩固性原则
【2015.广西】矮子里面挑高个的评价是()。
2010年,农村居民人均纯收入5919元,剔除价格因素,比上年实际增长10.9%;城镇居民人均可支配收入19109元,实际增长7.8%。农村居民家庭食品消费支出占消费总支出的比重为41.1%,城镇为35.7%。按2010年农村贫困标准1274元测算,年末农
举例说明,P、V操作为什么要求设计成原语(即对同一信号量上的操作必须互斥)。P(S)操作:S.value一一;if(S.value
在现在的雅典境内,西文先河谷的一个洞穴中有一组大约创造于1.5万年前的壁画,这些壁画描绘了不同种类的动物。其中一种动物看上去很像Lhirupos一爱琴海东边的一种河马。下列哪项,如果正确,最能支持以下假设,即在描绘像Lhirupos这种动物时,这位洞穴艺术
最新回复
(
0
)