Towards Verifiable Trust Management for Software Execution - (Extended Abstract).

Michael Huth, Jim Huan-Pu Kuo · 2013

Abstract. In the near future, computing devices will be present in most artefacts, will considerably outnumber the number of people on this planet, and will host software the executes in a potentially hostile and only partially known environment. This suggests the need for bringing trust management into running software itself, so that executing soft-ware be guard-railed by policies that reflect risk postures deemed to be appropriate for software and its deployment context. We sketch here an implementation of a prototype that realizes, in part, such a vision. The technical work described below relies on the concept of Trust Evidence. By this we mean any source of information (credentials, reputation, system state, past or present behavior, etc.) that can be used in order to assess the trustworthi-ness of running a unit of code. The variety of sources for Trust Evidence suggest the need for an extensible language in which such evidence can be combined. The quantitative (e.g. reputation) and qualitative (e.g. a claimed credential) na-ture of such evidence means that such a language has to consistently compose qualitative as well as quantitative notions of Trust Evidence. We here present an exploratory case study (whose usability issues are dis-cussed in [1]) where Scala [2] methods are the units of software that guard rails are meant to control. Guard rails use heterogeneous Trust Evidence sources to decide the circumstances in which methods may be invoked. The data-flow dia-gram of our case study, in Figure 1, has a three-layered guard rail architecture. Annotation blocks

Read the paper · More papers on PaperTik