The architecture of a secure group communication system based on intrusion tolerance
Miguel Pupo Correia, P. Verissino, Nuno Neves · 2002
This paper presents the architecture of a secure group communication system with the fortress model of trust, where the participants of the group equally trust one another. It considers that only a small part of the system, a component called the Trusted Timely Computing Base, has to be entirely trusted. All other components can be corrupted. The overall system will tolerate a certain number of faults of its components and remain behaving correctly.