Netinfo Security ›› 2016, Vol. 16 ›› Issue (9): 145-148.doi: 10.3969/j.issn.1671-1122.2016.09.029

• Orginal Article • Previous Articles     Next Articles

Trust Baseline Concept and Management Architecture

Qiang HUANG(), Zhiyin KONG, Le CHANG, Dehua ZHANG   

  1. Information Assurance Technology Laboratory, Beijing 100072, China
  • Received:2016-07-25 Online:2016-09-20 Published:2020-05-13

Abstract:

Based on the review of research history on security baseline and not only data but also system integrity protection ability provided by trusted computing platform, trust baseline concept was proposed to promote the traditional security baseline construction procedure and resolve actual problems of trust policy management in trusted computing platform deployment. Trust baseline concept is defined by the minimal guarantee of certain trust degree of information system. We emphasis the necessity of promotion of this concept with shortcoming of trust evaluation and analogy of security mechanism. On the basis of comparison of security baseline and trust baseline, the relationship of them is discussed and the function of trust baseline for providing system TCB assurance is presented. The trust baseline management structure was designed to contribute to trusted computing platform’s usage, arrangement and administration, combining trust and security mechanisms and policies and trust level evaluation.

Key words: trusted computing, trusted computing base, security baseline, trusted baseline, trust management

CLC Number: