Towards a cloud-based integrity measurement service

被引:3
|
作者
Zic, John [1 ]
Hardjono, Thomas [2 ]
机构
[1] CSIRO ICT Ctr, POB 76, Epping, NSW 1710, Australia
[2] MIT, MIT Kerberos & Internet Trust Consortium, Cambridge, MA 02139 USA
关键词
Authentication;
D O I
10.1186/2192-113X-2-4
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The aim of this paper is to propose the use of a cloud-based integrity management service coupled with a trustworthy client component -in the form of the Trust Extension Device (TED) platform - as a means to to increase the quality of the security evaluation of a client. Thus, in addition to performing authentication of the client (e.g. as part of Single Sign-On), the Identity Provider asks that the integrity of the client platform be computed and then be evaluated by a trustworthy and independent Cloud-based IntegrityMeasurement Service (cIMS). The TED platform has been previously developed based on the Trusted Platform Module (TPM), and allows the integrity measurement of the client environment to be conducted and reported in a secure manner. Within the SSO flow, the portable TED device performs an integrity measurement of the client platform, and sends an integrity report to the cIMS as part of the client authentication process. The cIMS validates the measurements performed by the TED device, and reports a trust score to the Identity Provider (IdP). The IdP takes into account the reported trust score when the IdP computes and issues a Level of Assurance (LOA) value to the client platform. In this way the Service Provider obtains a greater degree of assurance that the client's computing environment is relatively free of unrecognized and/ or unauthorized components.
引用
收藏
页码:1 / 9
页数:9
相关论文
共 50 条
  • [1] Quality of Service Measurement Mechanism of Cloud-Based Network Architecture
    Lai, Yung-Chang
    Jhan, Jhih-Dao
    Yang, Wen-Che
    Kuo, Fei-Hua
    Shih, Tai-Chueh
    [J]. 2019 20TH ASIA-PACIFIC NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM (APNOMS), 2019,
  • [2] Cloud-Based CAPTCHA Service
    Shumilov, Artem
    Philippovich, Andrey
    [J]. 2016 6TH INTERNATIONAL CONFERENCE - CLOUD SYSTEM AND BIG DATA ENGINEERING (CONFLUENCE), 2016, : 115 - 118
  • [3] Towards Cloud-based Analytics-as-a-Service (CLAaaS) for Big Data Analytics in the Cloud
    Zulkernine, Farhana
    Martin, Patrick
    Zou, Ying
    Bauer, Michael
    Gwadry-Sridhar, Femida
    Aboulnaga, Ashraf
    [J]. 2013 IEEE INTERNATIONAL CONGRESS ON BIG DATA, 2013, : 62 - 69
  • [4] Towards Cloud-Based Data Warehouse as a Service for Big Data Analytics
    Dabbechi, Hichem
    Nabli, Ahlem
    Bouzguenda, Lotfi
    [J]. COMPUTATIONAL COLLECTIVE INTELLIGENCE, ICCCI 2016, PT II, 2016, 9876 : 180 - 189
  • [5] DDOS Mitigation Cloud-Based Service
    Guenane, Fouad
    Nogueira, Michele
    Serhrouchni, Ahmed
    [J]. 2015 IEEE TRUSTCOM/BIGDATASE/ISPA, VOL 1, 2015, : 1363 - 1368
  • [6] Cloud-Based Manufacturing and Service Systems
    Chen, Tin-Chih Toly
    [J]. INTERNATIONAL JOURNAL OF INTELLIGENT SYSTEMS, 2017, 32 (04)
  • [7] Cloud-based Service-management
    不详
    [J]. CHEMIE INGENIEUR TECHNIK, 2021, 93 (11) : 1672 - 1672
  • [8] Cloud-Based Mobile Testing as a Service
    Tao, Chuanqi
    Gao, Jerry
    [J]. INTERNATIONAL JOURNAL OF SOFTWARE ENGINEERING AND KNOWLEDGE ENGINEERING, 2016, 26 (01) : 147 - 152
  • [9] A Cloud-based Service for Gamification of eGuides
    Swacha, Jakub
    Kulpa, Artur
    [J]. 2018 IEEE 6TH INTERNATIONAL CONFERENCE ON FUTURE INTERNET OF THINGS AND CLOUD WORKSHOPS (W-FICLOUD 2018), 2018, : 220 - 224
  • [10] RobotControl as a Service - Towards Cloud-based Motion Planning and Control for Industrial Robots
    Vick, Axel
    Vonasek, Vojtech
    Penicka, Robert
    Krueger, Joerg
    [J]. 2015 10TH INTERNATIONAL WORKSHOP ON ROBOT MOTION AND CONTROL (ROMOCO), 2015, : 33 - 39