Assurance Considerations for a Highly Robust TOE
نویسندگان
چکیده
The U.S. Government Protection Profile for Separation Kernels in Environments Requiring High Robustness (SKPP) is undergoing evaluation. During its authoring process, new extended functional and assurance requirements were introduced to resolve assurance issues associated with TOE hardware, trusted initialization and trusted recovery. For high robustness, domain separation and self-protection are architectural assurances only realistically achieved with hardware support. Since the Common Criteria does not include requirements for establishing assurance in security-relevant hardware mechanisms, a new Platform Assurance class was introduced. It provides a framework to determine the security relevance of commercially-available hardware based on its interfaces to software and to establish trust in those hardware mechanisms deemed security-relevant. Requirements for TOE initialization behavior and for establishing trust in that behavior are not prescribed in the CC Version 2.3. Although CC Version 3.1 does define secure initialization assurances, they are not sufficient for high robustness. A new Trusted Initialization assurance family was introduced to require a TOE initialization function that reliably establishes the TSF in an initial secure state, verifies TSF integrity during initialization, handles failures during initialization, does not arbitrarily interact with the TSF following TOE initialization, provides self-protection during initialization, and addresses the threat that the TSF is initialized by other components executing on the TOE. Existing trusted recovery requirements emphasize the means of failure handling (i.e., manual versus automated) instead of protecting against further compromise during a recovery from an insecure state to a secure state. Extended trusted recovery requirements were introduced to require the TSF to attempt self-recovery to a secure state when the TSF detects that it is in an insecure state. To avoid ambiguity, the TOE developer must enumerate pair-wise recovery conditions and their associated actions and provide appropriate evidence that secure state results from the identified action.
منابع مشابه
Enhanced Production and Characterization of a Highly Stable Extracellular Protease from an Extreme Halophilic Isolate Salicola marasensis
Owing to their superior catalytic activity in the extreme conditions, extremozymes have found the potential biotechnological applications for industrial purposes. A robust extracellular protease activity was detected in the culture broth of Salicola marasensis, an extreme halophilic bacterium, after a 48 h-incubation. The effect of different media ingredients in a liquid state fermentation was ...
متن کاملA quality assurance program for an amorphous silicon electronic portal imaging device using in-house developed phantoms: a method development for dosimetry purposes
Background: Electronic portal imaging devices (EPIDs) play an important role in radiation therapy portal imaging, geometric and dosimetric verifications. A successful utilization of EPIDs for imaging and dosimetric purposes requires a reliable quality control process routine to be carried out regularly. In this study, two in-house phantoms were developed and analyzed for implementation in a qua...
متن کاملEnhanced Production and Characterization of a Highly Stable Extracellular Protease from an Extreme Halophilic Isolate Salicola marasensis
Owing to their superior catalytic activity in the extreme conditions, extremozymes have found the potential biotechnological applications for industrial purposes. A robust extracellular protease activity was detected in the culture broth of Salicola marasensis, an extreme halophilic bacterium, after a 48 h-incubation. The effect of different media ingredients in a liquid state fermentation was ...
متن کاملHow Much Assurance Does a PIN Provide?
We would like to quantify the assurance contained in an authentication secret. For instance, how much assurance does a customer convey to a bank by revealing that his Personal Identification Number (PIN) is 1111? We review a number of previously proposed measures, such as Shannon Entropy and min-entropy. Although each is appropriate under some assumptions, none is robust regarding the attacker’...
متن کاملEnhancement of Robust Tracking Performance via Switching Supervisory Adaptive Control
When the process is highly uncertain, even linear minimum phase systems must sacrifice desirable feedback control benefits to avoid an excessive ‘cost of feedback’, while preserving the robust stability. In this paper, the problem of supervisory based switching Quantitative Feedback Theory (QFT) control is proposed for the control of highly uncertain plants. According to this strategy, the unce...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2007