[Prev]

7 Conclusion: TAS3 is Secure and Trustworthy

Comprehensive approach of the TAS3 architecture and framework achieves real and tangible overall security and trustworthiness gains when compared with state of the art for multiplayer networks of comparable size. TAS3 features that contribute to this are

  1. Legal concerns are built-in from the ground up

  2. A comprehensive and strong digitally signed audit trail

  3. A conditionally pseudonymous audit trail to guarantee the privacy of Users who play by the rules, while allowing abuse to be exposed through collaboration of Service Providers.

  4. A fully pseudonymous design at all layers to protect user privacy

  5. Fully encrypted and digitally signed messages using strong algorithms

  6. Based on state-of-the-art Single Sign-On protocol standard (SAML 2.0) which has had extensive security review

  7. Based on state-of-the-art Identity Web Service Protocol standards (ID-WSF 2.0) which have had extensive security review

  8. Enhanced authorization infrastructure which significantly improves upon the current XACMLv2 standard

  9. Ability to use risk control and reputation

  10. Use of ontologies to ensure consistent interpretation of data and authorization rules

  11. On-line Compliance Testing for early detection of discrepancies and problems

  12. Business Process Modelling driven configuration to ensure consistently correct configuration

  13. TAS3 has performed a systematic threat analysis (see Annex F) to ensure that the architecture addresses the widest possible range of security and privacy threats.

  14. Software engineering techniques used by the project to consistently achieve high quality and absence of security bugs in the software components that are TAS3 deliverables.

TAS3 Architecture is novel as a blueprint that brings together identity management, attribute based access control, business process modelling, and dynamic trust. The architecture, with Annex A, acts as an interoperability profile for various standards based protocols covering these areas. Other areas of innovation are user transparency features like Dashboard, user accessible audit trail, and automated compliance validation; privacy protection using sticky policies; marriage of trust and privacy Negotiation with discovery and trust scoring; secure dynamic business processes; and built-in first class support for delegation.


[Prev | Next]