首页
外语
计算机
考研
公务员
职业资格
财经
工程
司法
医学
专升本
自考
实用职业技能
登录
计算机
Trust is typically interpreted as a subjective belief in the reliability,honesty and security of an entity on which we depend (
Trust is typically interpreted as a subjective belief in the reliability,honesty and security of an entity on which we depend (
admin
2020-04-30
43
问题
Trust is typically interpreted as a subjective belief in the reliability,honesty and security of an entity on which we depend (71)________________ our welfare.In online environments we depend on a wide spectrum of things,ranging from computer hardware,software and data to people and organizations.A security solution always assumes certain entities function according to specific policies.To trust is precisely to make this sort of assumptions,hence,a trusted entity is the same as an entity that is assumed to function according to policy. A consequence of this is that a trusted component of a system must work correctly in order for the security of that system to hold,meaning that when a trusted (72)________________ fails,then the systems and applications that depend on it can (73)________________ be considered secure.An often cited articulation of this principle is:‘a trusted system or component is one that can break your security policy’(which happens when the trusted system fails).The same applies to a trusted party such as a service provider(SP for short),that is,it must operate according to the agreed or assumed policy in order to ensure the expected level of security and quality of services.A paradoxical conclusion to be drawn from this analysis is that security assurance may decrease when increasing the number of trusted components and parties that a service infrastructure depends on.This is because the security of an infrastructure consisting of many trusted components typically follows the principle of the weakest link,that is,in many situations the overall security can only be as strong as the least reliable or least secure of al l the trusted components.We cannot avoid using trusted security components,but the fewer the better.This is important to understand when designing the identity management architectures,that is,fewer the trusted parties in an identity management model,stronger the security that can be achieved by it.
The transfer of the social constructs of identity and trust into digital alld computational conceptshelpsindesigningandimplementinglarge scaleonlinemarketsandcommunities,and also plays an important role in the converging mobile and Internet environments.Identity management fdenoted IdM hereafter)is about recognizing and verifying the correctness of identities in online environments.Trust management becomes a component of (74)________________ whenever different parties rely on each other for identity provision and authentication.IdM and trust management therefore depend on each other in complex ways because the correctness of the identity itself must be trusted for the quality and reliability of the corresponding entity to be trusted.IdM is also an essential concept when defining authorisation policies in personalised services.
Establishing trust always has a cost,so that having complex trust requirements typically leads to high overhead in establishing the required trust.To reduce costs there will be incentives for stakeholders to‘cut comers’regarding trust requirements,which could lead to inadequate security.The challenge is tO design IdM systems with relatively simple trust requirements.Cryptographic mechanisms are often a core component of IdM solutions,for example,for entity and data authentication.With cryptography,it is often possible to propagate trust from where it initially exists to where it is needed.The establishment of initial (75)________________ usually takes place in the physical world,and the subsequent propagation of trust happens online,often in an automated manner.
选项
A、entity
B、person
C、component
D、thing
答案
C
解析
转载请注明原文地址:https://www.kaotiyun.com/show/kMTZ777K
本试题收录于:
信息安全工程师上午基础知识考试题库软考中级分类
0
信息安全工程师上午基础知识考试
软考中级
相关试题推荐
(2008上项管)以下关于成本基准特点的叙述中,不正确的是______。
(2010下集管)关于项目质量审计的叙述中,______是不正确的。
(2008上系管)运行Web浏览器的计算机与网页所在的计算机要建立______(1)连接,采用______(2)协议传输网页文件。(2)
(2012上集管)进度网络分析技术中的一种方法是______,它可以根据有限的资源对项目进度表进行调整。在确定了关键路线之后,将资源的有无与多寡考虑进去,确定资源制约进度表,并增加了持续时间缓冲段,这些持续时间缓冲段属于非工作计划活动。
(2011上项管)某异地开发的信息系统集成项目以程序流程图、数据流程图等为主要分析设计工具。由于用户身处异地,现场参与系统开发成本较高,因此项目组采用了先开发一个简化系统,待用户认可后再开发最终系统的策略。该信息系统集成项目的开发方法属于______。
(2013上项管)信息安全保障系统可以用一个宏观的三维空间来表示,第一维是OSI网路参考模型,第二维是安全机制,第三维是安全服务。该安全空间的五个要素分别是______。
(2010下软评)关于软件质量,______的叙述是正确的。①软件满足规定或潜在用户需求特性的总和;②软件特性的总和;软件满足规定用户需求的能力;③是关于软件特性具备“能力”的体现;④软件质量包括“代码质量”、“外部
(2014下集管)某系统集成项目的项目经理需采购第三方软件插件。在编制询价计划时,由于待采购软件插件比较专业,为了更加明确采购需求,该项目经理需要使用的文件为______。
某采购人在履行采购金额为1000万元的政府采购合同中,需要追加与该合同标的相同的货物。根据相关法律,在不改变合同其他条款的前提下,下列说法中正确的是()。
Typically, these are concern with the establishment of(66)the network and with the control of the flow of messages across this
随机试题
建立样条曲线的方法有:
追求股东利润最大化的企业价值观发展阶段是()
某化工厂向法院起诉,请求某纺织厂支付所拖欠的货款本息共计53万元。在诉讼过程中,纺织厂反诉要求化工厂赔偿由于所提供原料质量低劣造成的损失30万元。根据本案情况,下列选项中,法院的做法正确的有:
关于法定代理人对法院一审判决、裁定的上诉权,下列哪一说法是错误的?(2011年卷二22题,单选)
承包人在施工过程中应符合施工环境管理的有关要求,为此而发生的( )由发包人承担。
文化与文明是密切联系而又区别的两个范畴。二者的关系表现在:
人们在自我表露时通常遵循的原则是()
Completethetablebelow.WriteNOMORETHANONEWORDforeachanswer.
朋友之间过于随便,就容易侵入这片禁区。
A、Todobusiness.B、Tohaveinsurance.C、Toreducerisks.D、Toinvestmoney.C选项皆为不定式,推测题目可能询问某事件的目的。主讲人指出,保险的作用是降低和消除风险(toredu
最新回复
(
0
)