Trustworthy Global Computing - 9th International Symposium, TGC 2014, Rome, Italy, September 5-6, 2014. Revised Selected Papers

Trustworthy Global Computing - 9th International Symposium, TGC 2014, Rome, Italy, September 5-6, 2014. Revised Selected Papers
复制标题

可信赖的全球计算 - 第九届国际研讨会,TGC 2014,意大利罗马,2014 年 9 月 5-6 日。修订后的精选论文

DOI:
10.1007/978-3-662-45917-1_6
复制
发表时间:
2014
期刊:
--
影响因子:
--
通讯作者:
Cheval V
Cheval V
中科院分区:
--
文献类型:
--
作者:
Cheval V

文献摘要

相似文献

在某些情况下,确保强大的安全属性需要参与者在协议执行期间进行测试。一个典型的例子是电子投票:参与者被要求核实他们的选票是否出现在公告牌上,并核实选举结果的计算。证书透明性的概念是另一个例子,协议中的参与者需要执行测试来验证证书日志的完整性。我们使用应用的pi演算给出了一个框架来建模具有这种可测试性的系统。我们对参与者进行的测试进行建模,以获得安全属性。我们工作的基础是一种名为“恶意但谨慎”的攻击者模型,该模型介于多列夫-姚模型和“诚实但好奇”模型之间。这种恶意但谨慎的模式适用于那些可能怀有恶意,但被认为对发动可能导致用户测试失败的攻击持谨慎态度的云计算提供商。
Ensuring strong security properties in some cases requires participants to carry out tests during the execution of a protocol. A classical example is electronic voting: participants are required to verify the presence of their ballots on a bulletin board, and to verify the computation of the election outcome. The notion ofcertificate transparencyis another example, in which participants in the protocol are required to perform tests to verify the integrity of a certificate log.We present a framework for modelling systems with such ‘testable properties’, using the applied pi calculus. We model the tests that are made by participants in order to obtain the security properties. Underlying our work is an attacker model called “malicious but cautious”, which lies in between the Dolev-Yao model and the “honest but curious” model. The malicious-but-cautious model is appropriate for cloud computing providers that are potentially malicious but are assumed to be cautious about launching attacks that might cause user tests to fail.