Towards a cloud-based integrity measurement service

被引:3
|
作者
Zic, John [1 ]
Hardjono, Thomas [2 ]
机构
[1] CSIRO ICT Ctr, POB 76, Epping, NSW 1710, Australia
[2] MIT, MIT Kerberos & Internet Trust Consortium, Cambridge, MA 02139 USA
关键词
Authentication;
D O I
10.1186/2192-113X-2-4
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The aim of this paper is to propose the use of a cloud-based integrity management service coupled with a trustworthy client component -in the form of the Trust Extension Device (TED) platform - as a means to to increase the quality of the security evaluation of a client. Thus, in addition to performing authentication of the client (e.g. as part of Single Sign-On), the Identity Provider asks that the integrity of the client platform be computed and then be evaluated by a trustworthy and independent Cloud-based IntegrityMeasurement Service (cIMS). The TED platform has been previously developed based on the Trusted Platform Module (TPM), and allows the integrity measurement of the client environment to be conducted and reported in a secure manner. Within the SSO flow, the portable TED device performs an integrity measurement of the client platform, and sends an integrity report to the cIMS as part of the client authentication process. The cIMS validates the measurements performed by the TED device, and reports a trust score to the Identity Provider (IdP). The IdP takes into account the reported trust score when the IdP computes and issues a Level of Assurance (LOA) value to the client platform. In this way the Service Provider obtains a greater degree of assurance that the client's computing environment is relatively free of unrecognized and/ or unauthorized components.
引用
下载
收藏
页码:1 / 9
页数:9
相关论文
共 50 条
  • [31] Design of a Cloud-based Service Platform for the IoT
    Lo, Shou-Chih
    Kshirsagar, Varsha A.
    AD HOC & SENSOR WIRELESS NETWORKS, 2020, 47 (1-4) : 97 - 126
  • [32] EvacSys: A Cloud-Based Service for Emergency Evacuation
    Khalid, Osman
    Khan, Muhammad Usman Shahid
    Huang, Ying
    Khan, Samee U.
    Zomaya, Albert
    IEEE CLOUD COMPUTING, 2016, 3 (01): : 60 - 68
  • [33] GEA Cloud-based, open Service Portal
    不详
    FLEISCHWIRTSCHAFT, 2019, 99 (06): : 59 - 59
  • [34] TOWARDS SECURED CLOUD-BASED ROBOTIC SERVICES
    Nandhini, C.
    Doriya, Rajesh
    PROCEEDINGS OF 2017 IEEE INTERNATIONAL CONFERENCE ON SIGNAL PROCESSING AND COMMUNICATION (ICSPC'17), 2017, : 165 - 170
  • [35] Towards a Generic Cloud-Based Modeling Environment
    Juracz, Laszlo
    Howard, Larry
    DIGITAL INFORMATION PROCESSING AND COMMUNICATIONS, PT 1, 2011, 188 : 33 - 45
  • [36] Towards a Cloud-Based University Accelerated By the Pandemic
    Delgado Kloos, Carlos
    Alario-Hoyos, Carlos
    Fenandez-Panadero, Carmen
    Munoz-Merino, Pedro J.
    Estevez-Ayres, Iria
    Munoz-Organero, Mario
    Blanca Ibanez, Maria
    Manuel Moreno-Marcos, Pedro
    Garcia, Boni
    PROCEEDINGS OF THE 2021 IEEE GLOBAL ENGINEERING EDUCATION CONFERENCE (EDUCON), 2021, : 1648 - 1655
  • [37] Context-as-a-Service A Service Model for Cloud-Based Systems
    Moore, Philip
    Xhafa, Fatos
    Barolli, Leonard
    2014 EIGHTH INTERNATIONAL CONFERENCE ON COMPLEX, INTELLIGENT AND SOFTWARE INTENSIVE SYSTEMS (CISIS),, 2014, : 379 - 385
  • [38] Toward Data Integrity Architecture for Cloud-Based AI Systems
    Witanto, Elizabeth Nathania
    Oktian, Yustus Eko
    Lee, Sang-Gon
    SYMMETRY-BASEL, 2022, 14 (02):
  • [39] Study on cloud-based service platform for mass customization
    Che, Junhua
    Zeng, Qian
    Zhang, Shuyou
    ADVANCED MECHANICAL DESIGN, PTS 1-3, 2012, 479-481 : 98 - +
  • [40] A Cloud-Based Time-Dependent Routing Service
    Giannakopoulou, Kalliopi
    Kontogiannis, Spyros
    Papastavrou, Georgia
    Zaroliagis, Christos
    ALGORITHMIC ASPECTS OF CLOUD COMPUTING, ALGOCLOUD 2016, 2017, 10230 : 41 - 64