ACM Home Page
Please provide us with feedback. Feedback
Trust but verify: accountability for network services
Full text PdfPdf (132 KB)
Source ACM SIGOPS European Workshop archive
Proceedings of the 11th workshop on ACM SIGOPS European workshop table of contents
Leuven, Belgium
Article No. 37  
Year of Publication: 2004
Authors
Aydan R. Yumerefendi  Duke University
Jeffrey S. Chase  Duke University
Sponsor
SIGOPS: ACM Special Interest Group on Operating Systems
Publisher
ACM  New York, NY, USA
Bibliometrics
Downloads (6 Weeks): 10,   Downloads (12 Months): 42,   Citation Count: 4
Additional Information:

abstract   references   cited by   collaborative colleagues  

Tools and Actions: Review this Article  
DOI Bookmark: Use this link to bookmark this Article: http://doi.acm.org/10.1145/1133572.1133585
What is a DOI?

ABSTRACT

This paper promotes accountability as a central design goal for dependable networked systems. We define three properties for accountable systems that extend beyond the basic security properties of authentication, privacy, and integrity. These accountability properties reduce the vulnerability of network services to subversion, tampering, corruption, and abuse. For example, actions taken in accountable systems and their clients are provable or even legally binding, to support contractual relationships in federated systems.We propose a framework for accountable network services, and explore its applicability and limitations. The foundation of our approach is to preserve digitally signed records of actions and/or internal state snapshots of each service, and use them to detect tampering, verify the consistency of actions and behavior, and prove responsibility for unexpected states or actions. We outline the key challenges in generalizing the principles and methodology of accountable design for practical use.


REFERENCES

Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.

 
1
2
3
4
 
5
D. Hitz, J. Lau, and M. Malcolm. File System Design for an NFS File Server Appliance. In Proceedings of the USENIX Annual Technical Conference, pages 235--246, January 1994.
 
6
 
7
 
8
9
 
10
R. C. Merkle. Protocols for Public Key Cryptosystems. In Proceedings of the 1980 Sysmposium on Security and Privacy, pages 122--133, April 1980.
 
11
 
12
M. Naor and K. Nissim. Certificate Revocation and Certificate Update. IEEE Journal on Selected Areas in Communications, 18(4):561--570, 2000.
 
13
14
15
 
16
 
17
J. D. Strunk, G. R. Goodson, M. L. Scheinholtz, C. A. N. Soules, and G. R. Ganger. Self-Securing Storage: Protecting Data in Compromised Systems. In 4th Symposium on Operating System Design and Implementation (OSDI 2000), pages 165--180, October 23--25 2000.
 
18
B. Yee. Using Secure Coprocessors. PhD thesis, Carnegie Mellon University, May 1994.

Collaborative Colleagues:
Aydan R. Yumerefendi: colleagues
Jeffrey S. Chase: colleagues