SLIDE 10 ISSRG Information Systems Security Research Group Contact: d.w.chadwick@salford.ac.uk http://sec.isi.salford.ac.uk
Testing Application
- System Operation with no security
– attribute certificate is created by the client and then transmitted to the server using standard sockets – The recipient parses it into a data structure for easy access to any of its data elements
– attribute certificate is created by the client, digitally signed, and then transmitted to the server using standard sockets – The recipient firstly verifies the signature and then parses the certificate into a data structure for easy access to any of its data elements
- Used 3 complexities of attribute certificate
– Very Complex – auditCertificate (defined in a previous research project) – Semi-Complex – etpPrescribe certificate (defined by Dept of Health) – Simple – boolean attribute value