Chain of trust

Chain of trust

In computer security, a chain of trust is established by validating each component of hardware and software from the bottom up. It is intended to ensure that only trusted software and hardware can be used while still remaining flexible.

Introduction

A chain of trust is designed to allow multiple users to create and use software on the system, which would be more difficult if all the keys were stored directly in hardware. It starts with hardware that will only boot from software that is digitally signed. The signing authority will only sign boot programs that enforce security, such as only running programs that are themselves signed, or only allowing signed code to have access to certain features of the machine. This process may continue for several layers.

This process results in a chain of trust. The final software can be trusted to have certain properties, because if it had been illegally modified its signature would be invalid, and the previous software would not have executed it. The previous software can be trusted, because it, in turn, would not have been loaded if its signature would have been invalid. The trustworthiness of each layer is guaranteed by the one before, back to the Trust Anchor - the hardware.

It would be possible to have the hardware check the suitability (signature) for every single piece of software. However, this would not produce the flexibility that a "chain" provides. In a chain, any given link can be replaced with a different version to provide different properties, without having to go all the way back to the trust anchor. This use of multiple layers is an application of a general technique to improve scalability, and is analogous to the use of multiple certificates in a certificate chain.

Computer Security

In Computer Security, Digital certificates are verified using a chain of trust. The trust anchor for the digital certificate is the Root Certificate Authority (CA).

The Certificate Hierarchy is a structure of certificates that allows individuals to verify the validity of a certificate's issuer. Certificates are issued and signed by certificates that reside higher in the certificate hierarchy, so the validity and trustworthiness of a given certificate is determined by the corresponding validity of the certificate that signed it.

The Chain of Trust of a Certificate Chain is an ordered list of certificates, containing an end-user subscriber certificate and intermediate certificates (that represents the Intermediate CA), that enables the receiver to verify that the sender and all intermediates certificates are trustworthy.

Applications

One application of this mechanism is the Trusted Computing Group's vision based on the Trusted Platform Module. Although its proponents (including Microsoft) claim many benefits from this trust, most are convinced that the primary application is Digital Rights Management.



Wikimedia Foundation. 2010.

Игры ⚽ Поможем решить контрольную работу

Look at other dictionaries:

  • Trust Anchor — In cryptography,a Trust Anchor is an authoritative entity represented via a public key and associated data. It is used in the context of public key infrastructures and X.509 digital certificates.When there is a chain of trust, usually the top… …   Wikipedia

  • trust — [n1] belief in something as true, trustworthy assurance, certainty, certitude, confidence, conviction, credence, credit, dependence, entrustment, expectation, faith, gospel truth*, hope, positiveness, reliance, stock, store, sureness; concept 689 …   New thesaurus

  • chain — [n1] succession, series alternation, catena, concatenation, conglomerate, consecution, continuity, group, order, progression, row, sequence, set, string, syndicate, train, trust; concepts 432,727,769 chain [n2] connected metal links; jewelry made …   New thesaurus

  • Trust-Mart — A Trust Mart shop located in Guangzhou, China Trust Mart (Chinese: 好又多; pinyin: hǎoyòuduō) is a Taiwanese owned chain of Chinese retail supercenters. The corporation was founded in 1997 by investors based in Taiwan and as of March, 2006, had in… …   Wikipedia

  • Chain gang (cycling) — A chain gang or pace line In the sport of cycling, a chain gang is a group of cyclists in a close knit formation usually of two parallel lines. The formation comes from the fact that it is harder to cycle at the front of a group than in the… …   Wikipedia

  • Chain broadcasting — The notion of connecting two or more radio stations to broadcast the same program at the same time is said to have existed since the start of broadcasting. But chain broadcasting, also known as network broadcasting, actually began later.[1]… …   Wikipedia

  • chain — Synonyms and related words: Alps, Andes, Caucasus, Himalayas, Indian file, Kekule formula, Oregon boat, Rockies, accouple, accumulate, accumulative, additive, additory, agglutinate, alps on alps, alternation, amass, anchor, andiron, anklet,… …   Moby Thesaurus

  • trust — Synonyms and related words: Aktiengesellschaft, absolute interest, accept, accept for gospel, accept implicitly, acceptation, acception, acquiescence, agency, agentship, aktiebolag, arrogance, aspiration, aspire to, assign, assignment, assumption …   Moby Thesaurus

  • Web of trust — For the internet security website, see WOT: Web of Trust. In cryptography, a web of trust is a concept used in PGP, GnuPG, and other OpenPGP compatible systems to establish the authenticity of the binding between a public key and its owner. Its… …   Wikipedia

  • The Golden Chain — For the Catena Aurea of St. Thomas Aquinas, see Works by Thomas Aquinas. , who vouched for its authenticity; the FBI later also pronounced the document as genuine.Fact|date=December 2007Most accounts are vague on what year the Golden Chain… …   Wikipedia

Share the article and excerpts

Direct link
Do a right-click on the link above
and select “Copy Link”