Title :
Security for virtual private intranets
Author :
Arbaugh, William A. ; Davin, James R. ; Farber, David J. ; Smith, Jonathan M.
Author_Institution :
Distributed Syst. Lab., Pennsylvania Univ., Philadelphia, PA, USA
fDate :
9/1/1998 12:00:00 AM
Abstract :
As telecommuting grows, businesses must consider security when extending their network environment to employees´ homes. Researchers at the University of Pennsylvania have addressed the problem with smart cards, operating system modifications, and network authentication. We note the distinction between trust and integrity: trust is determined through the verification of components and the dependencies among them, while integrity demonstrates that components haven´t been modified. Thus integrity checking in a trustworthy system is about preserving an established trust or trust relationship. Our solution to the challenge of isolating functional roles that may share a single hardware platform is called secure identity based lending (SIBL). SIBL provides multiple personalities by partitioning the hard drive into n+1 partitions, where n is the number of supported personalities. All personalities use the system partition for core operating system components and shared applications. Each of the personalities is also associated with one of the remaining partitions, which are encrypted using a symmetric algorithm
Keywords :
Internet; home working; local area networks; security of data; smart cards; SIBL; businesses; core operating system components; employee homes; encryption; functional roles; hard drive; integrity checking; multiple personalities; network authentication; network environment; operating system modifications; secure identity based lending; security management; shared applications; single hardware platform; smart cards; symmetric algorithm; system partition; telecommuting; trust relationship; trustworthy system; virtual private intranets; Clouds; Companies; Cryptography; Data security; Home computing; Internet; Local area networks; Operating systems; Roads; Teleworking;