首页
外语
计算机
考研
公务员
职业资格
财经
工程
司法
医学
专升本
自考
实用职业技能
登录
计算机
Trust is typically interpreted as a subjective belief in the reliability,honesty and security of an entity on which we depend (
Trust is typically interpreted as a subjective belief in the reliability,honesty and security of an entity on which we depend (
admin
2020-04-30
12
问题
Trust is typically interpreted as a subjective belief in the reliability,honesty and security of an entity on which we depend (71)________________ our welfare.In online environments we depend on a wide spectrum of things,ranging from computer hardware,software and data to people and organizations.A security solution always assumes certain entities function according to specific policies.To trust is precisely to make this sort of assumptions,hence,a trusted entity is the same as an entity that is assumed to function according to policy. A consequence of this is that a trusted component of a system must work correctly in order for the security of that system to hold,meaning that when a trusted (72)________________ fails,then the systems and applications that depend on it can (73)________________ be considered secure.An often cited articulation of this principle is:‘a trusted system or component is one that can break your security policy’(which happens when the trusted system fails).The same applies to a trusted party such as a service provider(SP for short),that is,it must operate according to the agreed or assumed policy in order to ensure the expected level of security and quality of services.A paradoxical conclusion to be drawn from this analysis is that security assurance may decrease when increasing the number of trusted components and parties that a service infrastructure depends on.This is because the security of an infrastructure consisting of many trusted components typically follows the principle of the weakest link,that is,in many situations the overall security can only be as strong as the least reliable or least secure of al l the trusted components.We cannot avoid using trusted security components,but the fewer the better.This is important to understand when designing the identity management architectures,that is,fewer the trusted parties in an identity management model,stronger the security that can be achieved by it.
The transfer of the social constructs of identity and trust into digital alld computational conceptshelpsindesigningandimplementinglarge scaleonlinemarketsandcommunities,and also plays an important role in the converging mobile and Internet environments.Identity management fdenoted IdM hereafter)is about recognizing and verifying the correctness of identities in online environments.Trust management becomes a component of (74)________________ whenever different parties rely on each other for identity provision and authentication.IdM and trust management therefore depend on each other in complex ways because the correctness of the identity itself must be trusted for the quality and reliability of the corresponding entity to be trusted.IdM is also an essential concept when defining authorisation policies in personalised services.
Establishing trust always has a cost,so that having complex trust requirements typically leads to high overhead in establishing the required trust.To reduce costs there will be incentives for stakeholders to‘cut comers’regarding trust requirements,which could lead to inadequate security.The challenge is tO design IdM systems with relatively simple trust requirements.Cryptographic mechanisms are often a core component of IdM solutions,for example,for entity and data authentication.With cryptography,it is often possible to propagate trust from where it initially exists to where it is needed.The establishment of initial (75)________________ usually takes place in the physical world,and the subsequent propagation of trust happens online,often in an automated manner.
选项
A、SP
B、IdM
C、Internet
D、entity
答案
B
解析
转载请注明原文地址:https://jikaoti.com/ti/D1x7FFFM
本试题收录于:
信息安全工程师上午基础知识考试题库软考中级分类
0
信息安全工程师上午基础知识考试
软考中级
相关试题推荐
(2013下项管)以下关于商业智能的说法中,______是不恰当的。
(2013上项管)张某于2012年12月5日通过网银完成了四项支付,其中______的业务类型不同于其他三项。
(2010上项管)近年来,电子商务在我国得到了快速发展,很多网站能够使企业通过互联网直接向消费者销售产品和提供服务。从电子商务类型来说,这种模式属于______模式。
(2011下项管)下列描述中,______不是软件体系结构研究的内容。
(2010下集管)合同变更控制系统规定合同修改的过程,包括______。①文书工作;②跟踪系统;③争议解决程序;④合同索赔处理
(2009下项管)______不是成本估算的方法。
(2007上监理)利用数据统计方法控制质量的过程有:①进行统计分析;②判断质量问题;③收集整理质量数据;④拟订改进质量的措施;⑤分析影响质量的因素。其步骤是______。
(2009上集管)______的目的是评价项目产品,以确定其对使用意图的适合性,表明产品是否满足规范说明并遵从标准。
(2012上网工)802.11在MAC层采用了______协议。
(2007下项管)“消息”是我们所关心的实际数据,经常也称为“明文”,用“M”表示。经过加密的消息是“密文”,用“C”表示。如果用C=E(M)表示加密,M=D(C)表示解密。那么从数学角度讲,加密只是一种从M______的函数变换,解密正好是对加密的反函数
随机试题
商标
下列选项中,属于可持续发展对国际企业开展国际营销的要求的有()
DIC按发生快慢分哪几型?各型由哪些疾病引起?
有轻微局麻和阿托品样作用的镇咳药是
社会互适性主要是分析预测项目能否为当地的()所接纳,以及当地政府、居民支持项目的程度。
浅埋式地铁车站的出人口设置不宜少于()个。
已完成销售手续、但购买方在当月尚未提取的产品,销售方仍应作为本企业库存商品核算。()
现代公共行政的首要目标是公平正义。()
Clifcouldrunfastindeed.Andnobodyelseinhistowncouldrunfasterthanhe.SoClifwasproudofthisandalwaysreadyto
A、Itisthenameofariverboat.B、Itisapennameofafamouswriter.C、Itisatermofcommunicationamongpilots.D、Itisa
最新回复
(
0
)