Register

To become a member of ITProPortal Register here.

Already a member? Login here

Please register below. All we need is a valid email address and a password.

Please use a real email address as we need to email you to confirm your account.
Must be at least 6 characters long.

Benefits of joining ITProPortal:

  • Unlimited Access to Special Reports and White Papers
  • Exclusive offers and discounts
  • Free entry to all competitions
  • Access to beta sections of ITProPortal.com

Login to your account



Forgot your password?


End to End Trust – The Next Security Era?

End to End Trust – The Next Security Era?
  • Digg del.icio.us reddit Facebook

I was privileged to hear keynote speaker, George Stathakopolous, general manager of security engineering and communications at Microsoft give a follow up to his speech last year. 

George had kindly stepped in for Scott Charney VP of Trustworthy Computing at Microsoft and was talking about End to End Trust. 

If you would like to get the in-depth aspect of his talk you should read the complete report here.

Essentially end to end trust is about trying to find away to create a secure way of working by having access to a trusted stack.  The trusted stack is as follows

(1)   security rooted in the hardware
(2)   a trusted operating system
(3)   trusted applications
(4)   trusted people
(5)   trusted data.

Each of these layers are interdependent, and a breach in any part of the stack will undermine the security provided by the other layers. 

 

For example, a report may be created using secure hardware and a secure operating system by an authorised person and sent to another as a signed attachment with integrity with a trusted application but if the report itself is based on false data then the stack breaks down.  If on the other hand the data was sound but the application had been infected the model also breaks down.

In the next three blogs I’d like to focus on two aspects from this paper and talk and add one of my own:-

 
  • Beyond SD3
  • The Trusted Stack
  • Why the Trusted Stack Model can’t stack up
Ben Chai

Posted by Ben Chai on 02 July 2008

Ben Chai is a freelance writer and technical consultant. He is the author of several Microsoft books and is the co-owner of incomingthought.com, a company that specialises in security white papers.

Tags: Microsoft, information security, personal security