Automated cross-organisational trust establishment on extranets

被引:12
作者
Au, R [1 ]
Looi, M [1 ]
Ashley, P [1 ]
机构
[1] Queensland Univ Technol, Sch Data Commun, Informat Secur Res Ctr, Brisbane, Qld 4001, Australia
来源
PROCEEDINGS OF THE WORKSHOP ON INFORMATION TECHNOLOGY FOR VIRTUAL ENTERPRISES, ITVE 2001 | 2001年 / 23卷 / 06期
关键词
trust establishment; trust distribution; extranet; trust token; web of trust; trust agent; security server;
D O I
10.1109/ITVE.2001.904483
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Trust management is an important aspect of information security in an organisation. It involves the complexity of relationships among people, computers and the organisational system. It becomes even more complex in the virtual enterprise environment where cross-organisational activities are involved. This paper presents a new paradigm for establishing trust across multiple organisations for external users on extranets. In our approach, the authorities of organisations administer their local users and at the same time can act as trust agents for distributing trust management information for other users in the virtual enterprise. Trust is propagated in the form of trust tokens through the web of trust. After collecting these trust tokens as recommendations, a new users can submit them to his destined organisation in order to acquire secure trust relation. By representing trust with a quantitative and comparable value, an automated mechanism for composing trust tokens is demonstrated.
引用
收藏
页码:3 / 11
页数:9
相关论文
共 15 条
[11]  
KOHLAS R, 2000, LECT NOTES COMPUTER, V1751
[12]  
REITER MK, 1999, ACM T INFORMATION SY, V2
[13]  
VAZQUEZGOMEZ J, 1993, ACM PUBLICATION
[14]  
YAHALOM R, 1993, P 1993 IEEE S RES SE
[15]  
Zimmermann Philip R, 1995, The official PGP user's guide