You are here: silicon.com > Tags

17 stories on

attestation

Sort by: Date | Relevance


An Approach to a Trustworthy System Architecture Using Virtualization

whitepaper To achieve meaningful attestation, virtualization is used to establish several di? The attestation process is limited to a fragment of the software running on the platform, more specifically, to the part requesting access to sensitive data.

Tags: virtualization

[29 Feb 2008]

Flexible Integrity Protection and Verification Architecture for Virtual Machine Monitors

whitepaper It places particular emphasis on how those methods can be made extensible and flexible with the goal of obtaining a generic attestation and sealing framework for VMs. Lack of security of virtual machines and lack of trust into correct execution of...

Tags: security management

[29 Feb 2008]

Distributed Software-Based Attestation for Node Compromise Detection in Sensor Networks

whitepaper Based on verifying the genuineness of the running program, the paper proposes two distributed software-based attestation schemes that are well tailored for sensor networks. Sensors that operate in an unattended, harsh or hostile environment are...

Tags: monitoring systems, pseudorandom, attacks, distributed

[03 Sep 2007]

A Robust Integrity Reporting Protocol for Remote Attestation

whitepaper Trusted Computing Platforms provide the functionality of remote attestation, i.e.attesting the configuration and status of a system to a remote entity. Remote attestation hereby proves integrity and authenticity of system environments.

Tags: industry standard protocols, attacks, attestation, masquerading

[31 Aug 2007]

Distributed Software-Based Attestation for Node Compromise Detection in Sensor Networks

whitepaper Based on verifying the genuineness of the running program, the paper proposes two distributed software-based attestation schemes that are well tailored for sensor networks. Sensors that operate in an unattended, harsh or hostile environment are...

Tags: pseudorandom, memory, program, algorithm

[13 Aug 2007]

IT Control Objectives for Sarbanes-Oxley: The Importance of IT in the Design, Implementation and Sustainability of Internal Control Over Disclosure and Financial Reporting

whitepaper IT organizations need to become involved in Sarbanes-Oxley attestation activities quickly. While the US Securities and Exchange Commission (SEC) has extended the dates for compliance with Section 404 of the Act, this move was only an...

Tags: finance, sarbanes oxley, comply, guidance

[01 Aug 2007]

Layering Negotiations for Flexible Attestation

whitepaper It divides an attestation process into a global attestation phase that verifies that a Trusted Virtual Domains (TVD) is fundamentally secure and supporting essential trusted primitives and a local attestation phase that verifies the integrity of a...

Tags: security management, scenario, phase, trusted

[19 Jul 2007]

On Similarities Between SOA-Based Web Service and Smart Card Application for Ease of Understanding and Securing the Former

whitepaper Especially, its token services for attestation & authorization, and its cryptographic services for data confidentiality & integrity are detailed. This paper is to leverage familiarity with smart card application, i.e.understanding and practical...

Tags: card, soa, achieving, smart card

[08 Mar 2007]

Attestation of Identity Information

whitepaper This Oracle white paper discusses the fundamental premise of attestation and the role of identity management in achieving cost-effective, sustainable compliance. Attestation is the requirement that management periodically certifies that only...

Tags: firewalls, compliance, sarbanes oxley, identity

[04 Jan 2007]

Direct Anonymous Attestation

whitepaper This paper describes the direct anonymous attestation scheme (DAA). Direct anonymous attestation can be seen as a group signature without the feature that a signature can be opened, i.e.the anonymity is not revocable.

Tags: privacy issues, trusted, module, signature

[12 Apr 2005]

Sarbanes-Oxley Act (SOA) Section 404: Ensuring Data Integrity and Availability for Compliance and Attestation

whitepaper Now is the time to examine and improve your IT processes and systems for SOA compliance. Success depends upon the ability to initiate and maintain a disciplined methodology that reflects an institution's needs for IT controls as they relate to...

Tags: finance, compliance, controls, integrity

[23 Mar 2005]

Internal Controls Over Financial Reporting - The SEC's Rules Under Section 404 of the Sarbanes-Oxley Act

whitepaper The 404 Rules define standards for assessing internal controls over financial reporting and require an issuer to include in its annual report a management report on the effectiveness of its internal controls over financial reporting (internal...

Tags: sarbanes-oxley, controls, reporting, financial reporting

[23 Mar 2005]

Update: Internal Control Reports Under Section 404 of S-Ox - Auditing Standard Finalized and FAQs Published by SEC

whitepaper The OSC is currently undecided about whether to require external auditor attestation. Section 404 of the Sarbanes-Oxley Act of 2002 (S-Ox) and related U.S. SEC rules require the management of public companies to prepare an annual report on internal...

Tags: sarbanes-oxley, controls, internal controls, auditor

[23 Mar 2005]

Beyond Compliance - Leveraging Internal Control to Build a Better Business: A Response to Sarbanes-Oxley Sections 302 and 404

whitepaper A number of certification and attestation obligations are already in place. The Sarbanes-Oxley Act of 2002 is, by any standard, a complex piece of legislation, one that has engendered confusion and consternation in some quarters of the business...

Tags: finance, sarbanes oxley, oxley, response

[19 Dec 2004]

PeopleSoft Enterprise Meets Sarbanes-Oxley Section 404

whitepaper It will continue long after the first attestation. A successful Sarbox compliance initiative requires extensive communication among company departments, specifically between accounting, finance, treasury, and information technology.

Tags: sarbanes-oxley, compliance, savings, section

[16 Dec 2004]

Microsoft unveils the future of security

Microsoft unveils the future of security

News Four major features will be included in the first version of NGSCB: A technology called process isolation will seal off trusted applications so they can't be attacked; sealed storage will allow applications to store data securely; secure path will...

Tags: ngscb, security, microsoft

[07 May 2003]

Trusted computing 'can't be trusted'

Trusted computing 'can't be trusted'

News The feature, remote attestation, allows an application running on a computer to phone home and check that it's current status, or integrity, can be verified. Cryptographers and security firms took opposite sides over the potential privacy dangers...

Tags: trusted, rsa

[17 Apr 2003]

Sort by: Date | Relevance


Site Map    


Quick Sitemap Links: