Dynamic trust enhanced security model for trusted platform based services

被引:35
作者
Nagarajan, Aarthi [1 ]
Varadharajan, Vijay [1 ,2 ,3 ,4 ]
机构
[1] Macquarie Univ, Sydney, NSW 2109, Australia
[2] Univ Western Sydney, Sch Comp & IT, Penrith, NSW 1797, Australia
[3] Univ Plymouth, Plymouth PL4 8AA, Devon, England
[4] Univ Reading, Reading RG6 2AH, Berks, England
来源
FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE | 2011年 / 27卷 / 05期
关键词
Trusted computing; Attestation; Property attestation; Dynamic trust modelling;
D O I
10.1016/j.future.2010.10.008
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Binary attestation in trusted computing platforms provide the ability to reason about the state of a system using hash measurements. Property based attestation, an extension of binary attestation enables more meaningful attestation by abstracting low level binary values to high level security properties or functions of systems. In this paper, we propose TESM: A Trust Enhanced Secure Model for trusted computing platforms. We argue that given the nature of both binary and property based attestation mechanisms, an attestation requester cannot be absolutely certain if an attesting platform will behave as it is expected to behave. TESM uses a hybrid trust model based on subjective logic to combine 'hard' trust from measurements and properties and 'soft' trust from past experiences and recommendations to reduce such uncertainties. We believe that such a model will enable better reasoning about the trustworthiness of attesting platforms and thereby facilitate better security decision making. (C) 2011 Published by Elsevier B.V.
引用
收藏
页码:564 / 573
页数:10
相关论文
共 18 条
[1]  
[Anonymous], 2009, THESIS
[2]  
[Anonymous], 2006, TCG INFR WORK GROUP
[3]   Decentralized trust management [J].
Blaze, M ;
Feigenbaum, J ;
Lacy, J .
1996 IEEE SYMPOSIUM ON SECURITY AND PRIVACY, PROCEEDINGS, 1996, :164-173
[4]  
Blaze M., 1999, The keyNote trust-management system, Version 2
[5]  
DoD Computer Security Center, 1985, 520028STD DOD COMP S
[6]  
Grandison T., 2000, IEEE COMMUN SURG TUT, V3
[7]   A logic for uncertain probabilities [J].
Josang, A .
INTERNATIONAL JOURNAL OF UNCERTAINTY FUZZINESS AND KNOWLEDGE-BASED SYSTEMS, 2001, 9 (03) :279-311
[8]   Trust metrics, models and protocols for electronic commerce transactions [J].
Manchala, DW .
18TH INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS, PROCEEDINGS, 1998, :312-321
[9]  
Mui L., 2001, RATINGS DISTRIBUTED
[10]  
Nagarajan A., 2009, 3 INT C NETW SYST SE