Dissertation > Excellent graduate degree dissertation topics show
Trusted Network Connect access and authorization model design of the whole life cycle
Author: WangJiaHui
Tutor: WuZhenQiang
School: Shaanxi Normal University
Course: Computer Software and Theory
Keywords: Trusted Network Connection (TNC) entire Lifecycle evaluation trusted level fuzzy decision-making synthetic evaluation universally composable secure
CLC: TP393.08
Type: Master's thesis
Year: 2010
Downloads: 47
Quote: 0
Read: Download Dissertation
Abstract
|
With the increasing applications of embedded devices, consumer digital products, as well as a large number of sensors and other devices,the scale and applications of the Internet is continuing to expand, the influence and global role of the network in our lives is enhanced. But at the same time, the network also faces great security problems, spam, viruses and Trojan horse programs seriously endanger our lives. However, the existing network security measures are mostly aimed at the network perimeter to guard the terminal, the terminal lacks security management within the boundaries, bringing a serious impact on security solutions. Currently, solving network security issues from the endpoint have become a consensus. It has appeared in Cisco’s NAC, Microsoft’s NAP, TCG’s TNC, TNA of TOPSEC, Huawei’s EAD and many other terminal security access architecture, intending to solve the problems from the terminal. However, existing programs mostly focus on the integrity of the terminal when it accesses the network, the act after the terminal accesses network lack real-time control, this is not accordant with the actual situation of complex networks.The main contributions of this thesis are as follows after the solutions are researched in detail:1) Aiming at lack of management, an entire life cycle of Trusted Network access and authorization model is proposed, combining usage control model based on TNC specifications. This architecture not only ensure the integrity when the network terminal access the network based on the organization’s security policy, but also control the real-time behavior of the terminal through the changes of the properties and reliabilities.2) The integrity of the information is abstracted to the trusted level by fuzzy decision-making synthetic evaluation, and then the trusted level become a crucial part in the decision-making authority, realizing management of the entire life cycle when the terminal accesses the trusted network.3) A new authentication of accessing Trusted Network protocol is proposed. The identity authentication, platform authentication and integrity authentication are used to determine the corresponding permissions of the terminal, the security is proofed by Universally Composable Secure model.4) Application software is developed under the Linux operating system using a TPM simulator based on the model proposed in the thesis. Users can use TPM function through the graphical interfaces. The protocol authentication is proposed and tested in experimental platform.
|
Related Dissertations
- The Research of Malware Detection Technology Based on Active Mode,TP393.08
- Research of IRC Botnet Detection Based on Behavior,TP393.08
- Research on the Impact Analysis of Network Security Incidents Based on Simulation,TP393.08
- Topology Measurement and Security Analysis on Gnutella and eMule Network,TP393.08
- Implementation and Research of Illegal Websites Detection System Based on Comparison Methods,TP393.08
- Analysis and research -based HTTP proxy security gateway,TP393.08
- Association rule mining based Intrusion Detection System Research and Implementation,TP393.08
- The Research on Intrusion Detection System Based on Machine Learning,TP393.08
- Analysis and improvement of several e-cash payment scheme,TP393.08
- Research and Application of digital signature system based on smart cards,TP393.08
- The Solution of Information Systems Security in Financial Enterprise,TP393.08
- Design and Implementation of Secured Network Hard Disk System Based on USBKey Authentication,TP393.08
- Design and Implementation of Drive Level Trojan Transmission and Encryption Algorithms,TP393.08
- The Research of Attack Source Traceback in Distributed Denial-of-Service Attacks Based on VoIP,TP393.08
- The Design of Based on Port-Flow-Controled of LAN Optimization System,TP393.08
- Design and Implementation of the online bidding system for information security,TP393.08
- Research and Implementation of Bot Detection Based on API Hook Technology,TP393.08
- Research on Approximate String Matching and Its Application on URL Detection,TP393.08
- Research on Network Anomaly Detection Based on Projection Pursuit Regression,TP393.08
- Research on Checking and Digesting Policy Conflicts Under Multi-Policy Environments,TP393.08
- Research and Implementation of Embeded Web System Security,TP393.08
CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer applications > Computer network > General issues > Computer Network Security
© 2012 www.DissertationTopic.Net Mobile
|