ACM Home Page
Please provide us with feedback. Feedback
Trust management for trusted computing platforms in web services
Full text PdfPdf (99 KB)
Source
Conference on Computer and Communications Security archive
Proceedings of the 2007 ACM workshop on Scalable trusted computing table of contents
Alexandria, Virginia, USA
SESSION: Property-based attestation table of contents
Pages: 58 - 62  
Year of Publication: 2007
ISBN:978-1-59593-888-6
Authors
Aarthi Nagarajan  Macquarie University
Vijay Varadharajan  Macquarie University
Michael Hitchens  Macquarie University
Sponsors
SIGSAC: ACM Special Interest Group on Security, Audit, and Control
ACM: Association for Computing Machinery
Publisher
ACM  New York, NY, USA
Bibliometrics
Downloads (6 Weeks): 24,   Downloads (12 Months): 170,   Citation Count: 1
Additional Information:

abstract   references   cited by   index terms   collaborative colleagues  

Tools and Actions: Request Permissions Request Permissions    Review this Article  
DOI Bookmark: Use this link to bookmark this Article: http://doi.acm.org/10.1145/1314354.1314369
What is a DOI?

ABSTRACT

The concept of trusted platforms using trusted computing technology such as the Trusted Platform Module (TPM) is becoming significant in that such technologies are being increasingly available in PCs and mobile devices today. When such trusted platforms are used in applications, one of the key design issues is the ability to capture platform level requirements and to represent them as security policies for authorization decision making. This paper makes some contributions which we believe are an important first step in achieving policy based decision making with trusted platforms. It outlines a platform based trust management framework for specification of trust policies. In this context, we argue the need for a higher level abstraction that is able to capture the lower level state of the platform and use this in the evaluation of trust between the communicating entities. We extend the notion of trusted platform properties by introducing the concept of Component Property Certificates, which can be used in specifying and building trust relationships. We then illustrate how component property certificates can be used in the specification of trust policies of different granularities.


REFERENCES

Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.

 
1
Trusted Computer System Evaluation Criteria (TCSEC). 1985, Dept of Defense.
 
2
TCG TPM Main Specification Version 1.1b. 2005, Trusted Computing Group.
 
3
Balacheff, B., et al., Trusted Computing Platforms, TCPA Technology in Context, ed. S. Pearson. 2003: Hewlett-Packard Company. 322.
 
4
Poritz, J., et al., Property Attestation-Scalable and Privacy-Friendly Security Assessment of Peer Computers, in Technical Report RZ 3548. 2004, IBM Research.
5
 
6
Web Services Security: SOAP Message Security 1.1, wss-v1.1-spec-os-SOAPMessageSecurity, C. Kaler, Editor. 2006, OASIS Standard Specification.
 
7
Web Services Policy Framework (WS-Policy), Version 1.2. 2006, W3C.
 
8
Web Services Trust Language (WS-Trust). 2005, W3C.
 
9
 
10
 
11
 
12
 
13
 
14
Varadharajan, V. Authorization and Trust Enhanced Security for Distributed Applications. in Seventh International Conference on Information and Communications Security (ICICS). 2005. Beijing, China.
 
15
 
16
eXtensible Access Control Markup Language 3 (XACML) Version 2.0. 2005, OASIS. Enterprise Grid Security Requirements V1.1. 2005, Enterprise Grid Alliance Security Working Group.


Collaborative Colleagues:
Aarthi Nagarajan: colleagues
Vijay Varadharajan: colleagues
Michael Hitchens: colleagues