首页
外语
计算机
考研
公务员
职业资格
财经
工程
司法
医学
专升本
自考
实用职业技能
登录
计算机
Trust is typically interpreted as a subjective belief in the reliability,honesty and security of an entity on which we depend (
Trust is typically interpreted as a subjective belief in the reliability,honesty and security of an entity on which we depend (
admin
2020-04-30
28
问题
Trust is typically interpreted as a subjective belief in the reliability,honesty and security of an entity on which we depend (71)________________ our welfare.In online environments we depend on a wide spectrum of things,ranging from computer hardware,software and data to people and organizations.A security solution always assumes certain entities function according to specific policies.To trust is precisely to make this sort of assumptions,hence,a trusted entity is the same as an entity that is assumed to function according to policy. A consequence of this is that a trusted component of a system must work correctly in order for the security of that system to hold,meaning that when a trusted (72)________________ fails,then the systems and applications that depend on it can (73)________________ be considered secure.An often cited articulation of this principle is:‘a trusted system or component is one that can break your security policy’(which happens when the trusted system fails).The same applies to a trusted party such as a service provider(SP for short),that is,it must operate according to the agreed or assumed policy in order to ensure the expected level of security and quality of services.A paradoxical conclusion to be drawn from this analysis is that security assurance may decrease when increasing the number of trusted components and parties that a service infrastructure depends on.This is because the security of an infrastructure consisting of many trusted components typically follows the principle of the weakest link,that is,in many situations the overall security can only be as strong as the least reliable or least secure of al l the trusted components.We cannot avoid using trusted security components,but the fewer the better.This is important to understand when designing the identity management architectures,that is,fewer the trusted parties in an identity management model,stronger the security that can be achieved by it.
The transfer of the social constructs of identity and trust into digital alld computational conceptshelpsindesigningandimplementinglarge scaleonlinemarketsandcommunities,and also plays an important role in the converging mobile and Internet environments.Identity management fdenoted IdM hereafter)is about recognizing and verifying the correctness of identities in online environments.Trust management becomes a component of (74)________________ whenever different parties rely on each other for identity provision and authentication.IdM and trust management therefore depend on each other in complex ways because the correctness of the identity itself must be trusted for the quality and reliability of the corresponding entity to be trusted.IdM is also an essential concept when defining authorisation policies in personalised services.
Establishing trust always has a cost,so that having complex trust requirements typically leads to high overhead in establishing the required trust.To reduce costs there will be incentives for stakeholders to‘cut comers’regarding trust requirements,which could lead to inadequate security.The challenge is tO design IdM systems with relatively simple trust requirements.Cryptographic mechanisms are often a core component of IdM solutions,for example,for entity and data authentication.With cryptography,it is often possible to propagate trust from where it initially exists to where it is needed.The establishment of initial (75)________________ usually takes place in the physical world,and the subsequent propagation of trust happens online,often in an automated manner.
选项
A、with
B、on
C、of
D、for
答案
D
解析
转载请注明原文地址:https://kaotiyun.com/show/jMTZ777K
本试题收录于:
信息安全工程师上午基础知识考试题库软考中级分类
0
信息安全工程师上午基础知识考试
软考中级
相关试题推荐
(2010上系分)实施应用集成时,系统集成架构的选择对集成工作来说至关重要。某企业欲在其分布式异构环境中实现系统之间的协作能力,并保持系统之间的松散耦合。在这种要求下,采用______的系统架构最为合适。
(2011下项管)李先生是某软件开发公司负责某项目的项目经理,该项目已经完成了前期的工作进入实现阶段,但用户提出要增加一项新的功能,李先生应该______。
(2010下项管)某OA系统处于试运行阶段,用户反映不能登录,承建方现场工程师需要对导致该问题的各种原因进行系统分析,使用______工具比较合适。
(2011下集管)某项目经理正在进行活动资源估算,他可以采用的方法和技术中不包括______。
(2010上项管)IEEE802系列规范、TCP协议、MPEG协议分别工作在______。
(2009上软评)瀑布模型表达了一种系统的、顺序的软件开发方法。以下关于瀑布模型的正确叙述的是______。
(2008上项管)下图标明了六个城市(A~F)之间的公路(每条公路旁标注了其长度公里数)。为将部分公路改造成高速公路,使各个城市之间均可通过高速公路通达,至少要改造总计____(1)公里的公路,这种总公里数最少的改造方案共有____(2)个。(1)
(2005上项管)关于kerberos和PKI两种认证协议的叙述中正确的是______(1),在使用kerberos认证时,首先向密钥分发中心发送初始票据______(2)来请求会话票据,以便获取服务器提供的服务。(1)
(2010下集管)某信息系统集成项目实施期间,因建设单位指定的系统部署地点所处的大楼进行线路改造,导致项目停工一个月。由于建设单位未提前通知承建单位,导致双方在项目启动阶段协商通过的项目计划无法如期履行。根据我国有关规定,承建单位______。
a=17,b=2,则满足a与b取模同余的是(69)________________。
随机试题
自律性增高的因素是
最难酸水解的苷类为
建设工程招标投标计价方法的种类为()。
采用会计电算化软件的单位,其会计档案保管期限与手工核算时相比,应该()。
物业管理服务的()是物业服务合同区别一般委托合同的一个显著特点。
王某在某服装店挑选风衣,店员向王某推荐了一款。王某试穿后觉得不合适,便脱下来要走,店主却强迫王某买下了这件风衣。店主的这一行为侵犯了王某的()。
序列(8,9,10,4,5,6,20,1,2),只能是()排序方法两趟排序后的结果。
甲与乙共同出资购买别墅一套,后出租给某公司使用。在租赁期间,乙因缺钱花欲出让自己的共有份额。承租的公司表示愿意购买,则此房屋属于乙的份额应卖给()。
Doyouknowhowtouseamobilephonewithoutbeingrudetothepeoplearoundyou?Talkingduringaperformanceirritates(激怒)p
A、Attheman’sdormitory.B、Atthehall.C、Atoneclassroom.D、Atthelibrary.BWheredothestudentsarrangetomeet?
最新回复
(
0
)