16th IEEE Computer Security Foundations Workshop (CSFW'03)
On Distributed Security Transactions that Use Secure Transport Protocols
Pacific Grove, California
June 30-July 02
ISBN: 0-7695-1927-X
In this paper we consider techniques for designing and analysing distributed security transactions. We present a layered approach, with a high-level security transaction layer running on top of a lower-level secure transport protocol. The secure transport protocol provides protection against dishonest outsiders, while the transaction layer can be designed to provide protection against dishonest insiders. We specify generic services that one might expect such secure transport protocols to provide. We give examples of this layered approach, with the aim of demonstrating that the separation of concerns allows for a cleaner, more intuitive design. We consider how to analyse such a layered security architecture.