首页
外语
计算机
考研
公务员
职业资格
财经
工程
司法
医学
专升本
自考
实用职业技能
登录
计算机
Trust is typically interpreted as a subjective belief in the reliability,honesty and security of an entity on which we depend (
Trust is typically interpreted as a subjective belief in the reliability,honesty and security of an entity on which we depend (
admin
2020-04-30
51
问题
Trust is typically interpreted as a subjective belief in the reliability,honesty and security of an entity on which we depend (71)________________ our welfare.In online environments we depend on a wide spectrum of things,ranging from computer hardware,software and data to people and organizations.A security solution always assumes certain entities function according to specific policies.To trust is precisely to make this sort of assumptions,hence,a trusted entity is the same as an entity that is assumed to function according to policy. A consequence of this is that a trusted component of a system must work correctly in order for the security of that system to hold,meaning that when a trusted (72)________________ fails,then the systems and applications that depend on it can (73)________________ be considered secure.An often cited articulation of this principle is:‘a trusted system or component is one that can break your security policy’(which happens when the trusted system fails).The same applies to a trusted party such as a service provider(SP for short),that is,it must operate according to the agreed or assumed policy in order to ensure the expected level of security and quality of services.A paradoxical conclusion to be drawn from this analysis is that security assurance may decrease when increasing the number of trusted components and parties that a service infrastructure depends on.This is because the security of an infrastructure consisting of many trusted components typically follows the principle of the weakest link,that is,in many situations the overall security can only be as strong as the least reliable or least secure of al l the trusted components.We cannot avoid using trusted security components,but the fewer the better.This is important to understand when designing the identity management architectures,that is,fewer the trusted parties in an identity management model,stronger the security that can be achieved by it.
The transfer of the social constructs of identity and trust into digital alld computational conceptshelpsindesigningandimplementinglarge scaleonlinemarketsandcommunities,and also plays an important role in the converging mobile and Internet environments.Identity management fdenoted IdM hereafter)is about recognizing and verifying the correctness of identities in online environments.Trust management becomes a component of (74)________________ whenever different parties rely on each other for identity provision and authentication.IdM and trust management therefore depend on each other in complex ways because the correctness of the identity itself must be trusted for the quality and reliability of the corresponding entity to be trusted.IdM is also an essential concept when defining authorisation policies in personalised services.
Establishing trust always has a cost,so that having complex trust requirements typically leads to high overhead in establishing the required trust.To reduce costs there will be incentives for stakeholders to‘cut comers’regarding trust requirements,which could lead to inadequate security.The challenge is tO design IdM systems with relatively simple trust requirements.Cryptographic mechanisms are often a core component of IdM solutions,for example,for entity and data authentication.With cryptography,it is often possible to propagate trust from where it initially exists to where it is needed.The establishment of initial (75)________________ usually takes place in the physical world,and the subsequent propagation of trust happens online,often in an automated manner.
选项
A、with
B、on
C、of
D、for
答案
D
解析
转载请注明原文地址:https://kaotiyun.com/show/jMTZ777K
本试题收录于:
信息安全工程师上午基础知识考试题库软考中级分类
0
信息安全工程师上午基础知识考试
软考中级
相关试题推荐
(2009下集管)以质量为中心的信息系统工程控制管理工作是由三方分工合作实施的,这三方不包括______。
(2009下架构)软件架构贯穿于软件的整个生命周期,但在不同阶段对软件架构的关注力度并不相同,在______阶段,对软件架构的关注最多。
(2005上项管)当评估项目的成本绩效数据时,根据数据与基线的偏差程度将作出不同的反应。例如,10%的偏差可能不需作出反应,而100%的偏差将需要进行调查,对成本偏差的判断会使用______。
(2008下监理)网络计划中的虚工作_______(1)。双代号网络计划中的节点表示_______(2)。(2)
(2010上监理)支持较高传输速率的无线网络协议是______。
(2010上项管)IEEE802系列规范、TCP协议、MPEG协议分别工作在______。
(2005上软评)V模型指出,_______(1)对程序设计进行验证,______(2)对系统设计进行验证,_____(3)应当追溯到用户需求说明。(2)
(2005上软评)V模型指出,_______(1)对程序设计进行验证,______(2)对系统设计进行验证,_____(3)应当追溯到用户需求说明。(1)
(2013上项管)信息安全保障系统可以用一个宏观的三维空间来表示,第一维是OSI网路参考模型,第二维是安全机制,第三维是安全服务。该安全空间的五个要素分别是______。
(2010下集管)工作流(workflow)需要依靠______来实现,其主要功能是定义、执行和管理工作流,协调工作流执行过程中工作之间以及群体成员之间的信息交互。
随机试题
女,6岁,因反复水肿、尿少4周入院。查:血压90/68mmHg,尿蛋白+++,尿红细胞3~5个/HP,尿白细胞0~3个/HP,血浆白蛋白25g/L,Ch9mmol/L。BUN7mmol/L。该病人用泼尼松10mg,qid,治疗20天,尿量正常,水肿减
以下关于绩效薪金制的说法中错误的是()。
在交通拥挤地段,为了确保交通安全,规定机动车相互之间的距离d(米)与车速v(千米/小时)需遵循的关系是(其中a(米)是车身长,a为常量),同时规定d≥a/2.设机动车每小时流量,应规定怎样的车速,使机动车每小时流量Q最大.
缪勒和范德从社会技能发展的角度,把婴儿早期同伴交往划分为哪些阶段?()
离开了阶级斗争,就无法理解阶级社会的发展。“没有对抗就没有进步。这是文明直到今天所遵循的规律”。阶级斗争是
What’saman?Or,indeed,awoman?Biologically,theanswermightseemobvious.Ahumanbeingisa(n)【C1】______whohasgrownfr
UPS的中文译名是()。
Readthememoandtheadvertisementbelow.Completetheformbelow.Writeawordorphrase(inCAPITALLETTERS)oranumberonlin
Theslogan"scientifictruthisamatterofsocialauthority"hasbecomedogmatomanyacademicinterestgroupswhohavebeen__
WhatarethechallengesfacingmultinationalsthatwanttobuildtheirbrandsinChina?—Ithinkthefirstthingisignorance.T
最新回复
(
0
)