Publication | Closed Access
Trust-based security in pervasive computing environments
281
Citations
0
References
2001
Year
Authentication AuthorizationMobile SecurityEngineeringInformation SecurityTrust Management ArchitectureHardware SecurityAccess ControlTrust-based SecurityAuthentication ProtocolAuthenticationData PrivacyTrustComputer ScienceMobile ComputingData SecurityCryptographyTrustworthy ComputingTrusted SystemCloud ComputingAccess Control ProblemsSerious Security RisksAuthentication Access Control
Traditional stand‑alone computers rely on user authentication and access control, but these methods are inadequate for distributed pervasive computing environments lacking central control and with mobile users, creating serious security risks. The authors propose a trust‑based security solution that develops a policy, assigns credentials, verifies compliance, delegates trust, and reasons about users' access rights. The solution employs trust management to implement these steps in pervasive computing environments.
Traditionally, stand-alone computers and small networks rely on user authentication and access control to provide security. These physical methods use system-based controls to verify the identity of a person or process, explicitly enabling or restricting the ability to use, change, or view a computer resource. However, these strategies are inadequate for the increased flexibility that distributed networks such as the Internet and pervasive computing environments require because such systems lack central control and their users are not all predetermined. Mobile users expect to access locally hosted resources and services anytime and anywhere, leading to serious security risks and access control problems. We propose a solution based on trust management that involves developing a security policy, assigning credentials to entities, verifying that the credentials fulfill the policy, delegating trust to third parties, and reasoning about users' access rights. This architecture is generally applicable to distributed systems but geared toward pervasive computing environments.