RE: TCPA Enabled Open Source Platforms

D Lambrou <[email protected]> 13 Dec 2003 03:15:39 +0200
Newsgroups gmane.comp.security.papers
Message-ID <1071278141.12388.49.camel@crazy>
On Fri, 2003-12-12 at 23:24, Kelly Winters wrote:
> 
> In the interest of equal time, here's a link to some discussion from the
> other camp.
> 
> http://www.notcpa.org/boards/

The paper title is "TCPA enabled Open Source Platforms". It is the Open
Source that I am focusing on.Most NOTCPA arguments might be true for
proprietary systems.I will not comment on the specific arguments as it
has been discussed a lot.

3. Open source and Trusted platforms

    * 3.1 In Social Trust we trust?
    * 3.2 The ultimate Trusted Platform
          o 3.2.1 Trust Relationships in an Open Source environment
          o 3.2.2 Validating a Platform identity 
    * 3.3 Issues of Open Source and TCPA
    * 3.4 Criticisms about TCPA
    * 3.5 The future of TCPA 

I do have knowledge of the other camp. I see TCPA as a technology. It
will serve all sorts of applications. And I really cant see TCPA going
away.

Some applications may be unanimously accepted and some might be not be
accepted by the public. Applying TCPA in an Open Source platform (from
BBB to kernel, next step can be www.opencores.org) and having members of
the Open Source community to monitor the process of TCPA certification
(for Open SOurce platforms), sounds like ideal to me.
With the industry support , Linux will evolve to a more stable and maybe
certified OS. And Open Source and security eval. can have more value
than sec. eval. for closed systems. 

The common problem when it comes to security:
 Some of the data you protect may belong to entities like:

- Digital Media Comp.
- National Security Authority
- Software Comp.
- Mafia

- The paper focuses on Open Source Software.In an Open Source
environment.(sounds like a utopia maybe)
- Cryptography offers the same dillema for the above entities.
Cryptography is not banned though. It might protect your personal data,
but it will protect the "bad guy's" data as well.(TCPA serves both
sides, bad guys might be all of the above for some)
- Changes to the specification have been proposed to make the TCPA spec
state clearly its goal and allow better "customization". 

William A. Arbaugh.
Improving the TCPA specification.
IEEE Computer, pages 77-79, August 2002.

TCPA would be ideal if it was Open Source. I will not go into more
detail. More can be found in the thesis (Chapter 3).

A last note. TCPA as it stands cannot support the full fledged Palladium
OS.And dont forget there is no perfect security.Its all a tradeoff
(investement/data value/ease of use). 

Best 
Demetrios


> 
> 
> -----Original Message-----
> From: D Lambrou [mailto:[email protected]]
> Sent: Friday, December 12, 2003 5:32 AM
> To: [email protected]
> Subject: TCPA Enabled Open Source Platforms
> 
> 
> "TCPA Enabled Open Source Platforms"
> Demetrios Lambrou
> 
> Abstract:
> 
> TCPA is a technology that has been heavily critised when it was first
> brought to the public. However TCPA is a promising technology which can
> be used to enhance the Trusted base of the OS to provide security
> enhanced services, with focus on confidentiallity of user data, in a
> cost effective way.
> The applications of a TCPA enabled platform can be of use for many
> different computing environments.
> This paper describes the main features of the technology with focus on
> the TCPA agent for the Linux OS.
> In addition it describes some of the problems and possible solutions
> ,about implementing TCPA, effectively, in a trully Open Source
> environment.
> 
> http://crazylinux.net/projects/downloads/TCPA/TCPA_thesis.html
> 
> 
> http://crazylinux.net/security.htm
> 
> 
> --
> ---------------------------------------------------------
> D Lambrou
> http://crazylinux.net
> 
> You can always get my public key block from
> http://crazylinux.net/public.asc
> Fingerprint: C7B3 A112 3704 7202 2B33  6B28 5418 78DD 774A 7BCB
> 
> 
> 
-- 
---------------------------------------------------------
D Lambrou
http://crazylinux.net

You can always get my public key block from
http://crazylinux.net/public.asc
Fingerprint: C7B3 A112 3704 7202 2B33  6B28 5418 78DD 774A 7BCB