Content authentication in enterprises for mobile devices
Martin Kappes, P. Krishnan · 2004
Most recent work in enterprise security has targeted the area of securing systems and networks from external hackers. We present new security challenges that arise in such networks from a mobile workforce. We argue that future threats to the network will likely come from inside the network; specifically, from legitimate devices and users that roam and reconnect to the enterprise. Fundamentally, most current and past work tackles the issue of authenticating a user or a machine (its hardware) before allowing access to enterprise resources. However, we expect that the critical issue going forward will be to authenticate the content of a device and ensure that the content is in-line with the enterprise's security polices. In this paper, we present a framework for authenticating the contents of devices connecting to an enterprise and also propose a new token-based scheme for indirect content authentication.