首页> 外文学位 >Securing Secrets and Managing Trust in Modern Computing Applications
【24h】

Securing Secrets and Managing Trust in Modern Computing Applications

机译:保护现代计算应用程序中的秘密并管理信任

获取原文
获取原文并翻译 | 示例

摘要

The amount of digital data generated and stored by users increases every day. In order to protect this data, modern computing systems employ numerous cryptographic and access control solutions. Almost all of such solutions, however, require the keeping of certain secrets as the basis of their security models. How best to securely store and control access to these secrets is a significant challenge: such secrets must be stored in a manner that protects them from a variety of potentially malicious actors while still enabling the kinds of functionality users expect.;This dissertation discusses a system for isolating secrets from the applications that rely on them and storing these secrets via a standardized, service-oriented secret storage system. This "Secret Storage as a Service" (SSaaS) model allows users to reduce the trust they must place in any single actor while still providing mechanisms to support a range of cloud-based, multi-user, and multi-device use cases.;This dissertation contains the following contributions: an overview of the secret-storage problem and how it relates to the security and privacy of modern computing systems and users, a framework for evaluating the degree by which one must trust various actors across a range of popular use cases and the mechanisms by which this trust can be violated, a description of the SSaaS model and how it helps avoid such trust and security failures, a discussion of how the SSaaS approach can integrate with and improve the security of a range of applications, an overview of Custos -- a first-generation SSaaS prototype, an overview of Tutamen -- a next-generation SSaaS prototypes, and an exploration of the legal and policy implications of the SSaaS ecosystem.
机译:用户生成和存储的数字数据量每天都在增加。为了保护这些数据,现代计算系统采用了许多密码和访问控制解决方案。但是,几乎所有此类解决方案都要求保留某些机密作为其安全模型的基础。如何最好地安全地存储和控制对这些秘密的访问是一个巨大的挑战:必须以一种保护它们免受各种潜在恶意行为者的方式存储这些秘密,同时仍然启用用户期望的各种功能。用于将机密与依赖它们的应用程序隔离,并通过标准化的,面向服务的机密存储系统存储这些机密。这种“秘密存储即服务”(SSaaS)模型允许用户减少他们必须在任何单个参与者中建立的信任,同时仍然提供支持一系列基于云,多用户和多设备的用例的机制。本论文包含以下贡献:秘密存储问题的概述以及它与现代计算系统和用户的安全性和隐私性之间的关系,用于评估人们在广泛使用范围内必须信任各种参与者的程度的框架违反这种信任的案例和机制,SSaaS模型的描述及其如何避免这种信任和安全性失败,SSaaS方法如何与各种应用程序集成并提高其安全性的讨论, Custos概述(第一代SSaaS原型),Tutamen概述(下一代SSaaS原型)以及SSaaS生态系统的法律和政策含义的探索。

著录项

  • 作者

    Sayler, Andy.;

  • 作者单位

    University of Colorado at Boulder.;

  • 授予单位 University of Colorado at Boulder.;
  • 学科 Computer science.;Public policy.;Information technology.
  • 学位 Ph.D.
  • 年度 2016
  • 页码 212 p.
  • 总页数 212
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号