« ALEA Home | Email msg. | Reply to msg. | Post new | Board info. Previous | Home | Next

Parallel universes

By: Cactus Flower in ALEA | Recommend this post (0)
Fri, 06 Apr 12 9:37 PM | 76 view(s)
Boardmark this board | The Trust Matrix
Msg. 07223 of 54959
Jump:
Jump to board:
Jump to msg. #

I hear the sound of self-congratulation in the air.

From the prophet alea in 2002:

"The crux of my argument is that in order to accommodate this need a new, parallel, trust framework resembling that with which we are familiar outside the virtual world needs to be put in place within it. It won’t replace the public internet as we know it. But it will flow along the same pipes, and end up in the same devices. This framework, which within society manifests itself in our everyday interactions, in local customs, laws and in a global financial system, will need to be translated into the encrypted language of the network.

This will be achieved by making two structural changes to the network architecture: first, through alterations to the design of the user’s device; and second, through crystallization of the role of the device’s user. Both of these changes will be built at the periphery of the network, and based on the inclusion of a new specialized chip, or sequence of chips, in the heart of every connected machine.

...The chief difference of this architecture is that it not only protects the individual device from assault. It protects the data stream as well. If parts of a system are secure and other parts insecure, then security is organized as if the protected spaces are data islands to which people have only provisional access. This is the world of firewalls, intranets and fortress servers, such as we see today. But where we have a system that is secure at every node, and in which the data between nodes is encrypted, then in effect you have created a secure corridor for the universal dissemination of valuable, or sensitive information. And this is something quite different. It provides a whole new, parallel data structure that uses the same pipes and the same devices as the public internet, but functions quite differently from it.

With security, of course, the proof of the pudding is in the eating. We will not be in a position to weigh the success of the structure until it is broadly tested in the marketplace. The hope, of course, is that the robustness of this system is sufficient that the insurance industry will be willing to write policies against the remaining risk of loss. The cost of the premium will be the final arbiter of the value of the security in a client-side architecture.

...A second objection to the adoption of this architecture surrounds the notion that any restriction negates a person’s inherited freedom to operate his computer as he wishes. Software developers are used to the notion that the virtual world is their oyster. The introduction of a secure architecture is an annoying piece of grit.

But it is an equally well-established rule that an individual’s freedom extends only so far as it does another no harm. We have seen that in the absence of protection, people have chosen to ignore the law and make the copy: and not in the one’s and two’s but in the hundreds and thousands.

As far as seems possible, the introduction of a vault, which is used at the option of the user, honors both principles. A person can do what he likes with his device while the copyright mechanism is switched off. And he can have access to copyright-protected data when it is switched on. Any content that is available within the “digital commons” – that is, information that authors and artists have deliberately placed in the public domain, or that becomes part of it due to the elapse of time - will remain so. Indeed, the idea of parallel data universes reflects rather accurately the two very different informational structures we encounter in the tangible world: the free model that exists in libraries and universities, as opposed to the valuable model that illuminates the commercial world beyond."

From Sarayu in 2012:

http://www.americanbanker.com/issues/177_66/ARM-Gemalto-Giesecke-Devrient-form-mobile-security-joint-venture-1048128-1.html

ARM, Gemalto and Giesecke & Devrient this week announced the creation of a joint venture dedicated to creating secure hardware for mobile devices, including tablets, smart-TVs, games consoles and smartphones. All three companies will contribute assets to the new venture, including patents, software, people, cash and capital equipment. ARM will own 40% of the joint venture, with Gemalto and Giesecke & Devrient each owning 30%. The joint venture is subject to regulatory approval.

The three companies say the joint venture's new technology will be based on their existing solutions. London-based ARM, for instance, offers TrustZone hardware, a chip that can host two operating systems, one less secure (such as Android or iOS) and one more secure, such as Munich-based Giesecke & Devrient's MobiCore "trusted execution environment." These two technologies together offer a parallel world for mobile applications: a normal-security environment in which non-sensitive applications run and a more secure environment for sensitive applications. The new venture will develop a Trusted Execution Environment based on the ARM TrustZone security technology.

Gemalto, which is based in Amsterdam, also provides software for securing data and applications on mobile devices, as well as chips for debit and credit cards. It will contribute software expertise to the joint venture.


- - - - -
View Replies (1) »



» You can also:
« ALEA Home | Email msg. | Reply to msg. | Post new | Board info. Previous | Home | Next