首页
外语
计算机
考研
公务员
职业资格
财经
工程
司法
医学
专升本
自考
实用职业技能
登录
计算机
Trust is typically interpreted as a subjective belief in the reliability,honesty and security of an entity on which we depend (
Trust is typically interpreted as a subjective belief in the reliability,honesty and security of an entity on which we depend (
admin
2020-04-30
37
问题
Trust is typically interpreted as a subjective belief in the reliability,honesty and security of an entity on which we depend (71)________________ our welfare.In online environments we depend on a wide spectrum of things,ranging from computer hardware,software and data to people and organizations.A security solution always assumes certain entities function according to specific policies.To trust is precisely to make this sort of assumptions,hence,a trusted entity is the same as an entity that is assumed to function according to policy. A consequence of this is that a trusted component of a system must work correctly in order for the security of that system to hold,meaning that when a trusted (72)________________ fails,then the systems and applications that depend on it can (73)________________ be considered secure.An often cited articulation of this principle is:‘a trusted system or component is one that can break your security policy’(which happens when the trusted system fails).The same applies to a trusted party such as a service provider(SP for short),that is,it must operate according to the agreed or assumed policy in order to ensure the expected level of security and quality of services.A paradoxical conclusion to be drawn from this analysis is that security assurance may decrease when increasing the number of trusted components and parties that a service infrastructure depends on.This is because the security of an infrastructure consisting of many trusted components typically follows the principle of the weakest link,that is,in many situations the overall security can only be as strong as the least reliable or least secure of al l the trusted components.We cannot avoid using trusted security components,but the fewer the better.This is important to understand when designing the identity management architectures,that is,fewer the trusted parties in an identity management model,stronger the security that can be achieved by it.
The transfer of the social constructs of identity and trust into digital alld computational conceptshelpsindesigningandimplementinglarge scaleonlinemarketsandcommunities,and also plays an important role in the converging mobile and Internet environments.Identity management fdenoted IdM hereafter)is about recognizing and verifying the correctness of identities in online environments.Trust management becomes a component of (74)________________ whenever different parties rely on each other for identity provision and authentication.IdM and trust management therefore depend on each other in complex ways because the correctness of the identity itself must be trusted for the quality and reliability of the corresponding entity to be trusted.IdM is also an essential concept when defining authorisation policies in personalised services.
Establishing trust always has a cost,so that having complex trust requirements typically leads to high overhead in establishing the required trust.To reduce costs there will be incentives for stakeholders to‘cut comers’regarding trust requirements,which could lead to inadequate security.The challenge is tO design IdM systems with relatively simple trust requirements.Cryptographic mechanisms are often a core component of IdM solutions,for example,for entity and data authentication.With cryptography,it is often possible to propagate trust from where it initially exists to where it is needed.The establishment of initial (75)________________ usually takes place in the physical world,and the subsequent propagation of trust happens online,often in an automated manner.
选项
A、with
B、on
C、of
D、for
答案
D
解析
转载请注明原文地址:https://kaotiyun.com/show/jMTZ777K
本试题收录于:
信息安全工程师上午基础知识考试题库软考中级分类
0
信息安全工程师上午基础知识考试
软考中级
相关试题推荐
(2010上集管)一项新的国家标准出台,某项目经理意识到新标准中的某些规定将导致其目前负责的一个项目必须重新设定一项技术指标,该项目经理首先应该______。
(2013上项管)某系统集成公司的变更管理程序中有如下规定:“变更控制委员会由公司管理人员、甲方主管、项目经理、关键开发人员、关键测试人员、质量保证代表和配置管理代表组成。变更控制委员会的职责为:批准基线的建立和配置项的确定;代表项目经理和所有可能基线变更
(2014下集管)根据《信息技术软件工程术语GB/T11457—2006》的规定,______是计算机程序中的一个点,在此点检验或记录程序的状态、状况或结果。
(2012上网工)802.11在MAC层采用了______协议。
(2008上项管)下图标明了六个城市(A~F)之间的公路(每条公路旁标注了其长度公里数)。为将部分公路改造成高速公路,使各个城市之间均可通过高速公路通达,至少要改造总计____(1)公里的公路,这种总公里数最少的改造方案共有____(2)个。(2)
(2007下项管)组织是由人和其他各种用以实现一系列目标的资源组成的正式集合。所有的组织都包含有一系列的增值过程,如内部后勤、仓库和存储、生产、市场、销售、客户服务等等,这些是______(1)的组成部分,信息系统在增值过程中,______(2)。组织适应
(2009上集管)(2008上项管)在项目管理的下列四类风险类型中,对用户来说如果没有管理好,______将会造成最长久的影响。
(2011上集管)在某次针对数据库的信息安全风险评估中,发现其中对财务核心数据的逻辑访问密码长期不变。基于以上现象,下列说法正确的是______。
Typically, these are concern with the establishment of(66)the network and with the control of the flow of messages across this
For users, microkernel technology promises(90), compact and sophisticated operating systems that are typically(91)across a range
随机试题
A.磨切基牙牙体组织较少的是哪一种固定桥B.倒凹区牙面与基牙长轴之间构成角度C.就位道与脱位道之间形成的角度D.模型固定在观测台上,牙冠轴面最突点所画出的连线E.用来确定基牙的倒凹区和非倒凹,选择卡环类型,确定义齿共同就位道的仪器下述内容中,与
最常转移到局部淋巴结的肿瘤是
A.呋喃唑酮B.甲氧苄啶C.氧氟沙星D.磺胺嘧啶E.甲硝唑能引起儿童软骨发育不良的药物是()
根据《国务院关于投资体制改革的决定》,实行备案制的企业投资项目,一般由企业按属地原则向地方政府()备案。
利用气体火焰的热能将工件切割处预热到一定温度后喷出高速切割氧流,使金属燃烧并放出热量而实现切割的方法是( )。
人的抗辩,又称相对抗辩或主观抗辩,是票据债务人仅可以对特定的票据债权人提出的抗辩,包括()的抗辩。
公民、法人或者其他组织认为具体行政行为侵犯其合法权益的,可以自知道该具体行政行为之日起一定期限内提出行政复议申请,该期限为( )。
我国《婚姻法》规定,结婚必备的条件有
已知事件A与B互不相容,则=_______,=______,=______.
下列程序的运行结果是()。#includemain(){staticchara[]="Languagef",b[]="programe";char*p1,*p2;intk;p1
最新回复
(
0
)