论文标题
迈向加密性评估的成熟模型
Towards a maturity model for crypto-agility assessment
论文作者
论文摘要
这项工作提出了加密性成熟度模型(简称CAMM),这是确定给定软件或IT景观的加密性状态的成熟度模型。 CAMM由五个级别组成,对于每个级别,根据文献综述,已经制定了一组要求。现场专家的初步反馈证实,CAMM具有精心设计的结构,并且易于理解。基于我们的模型,可以系统地测量和逐步改进IT景观的冷冻学敏捷性。我们预计这将使公司能够对破碎的密码方案造成的威胁做出更好和更快的反应。这项工作旨在促进CAMM,并鼓励其他人将其应用于实践并共同发展。
This work proposes the Crypto-Agility Maturity Model (CAMM for short), a maturity model for determining the state of crypto-agility of a given software or IT landscape. CAMM consists of five levels, for each level a set of requirements have been formulated based on literature review. Initial feedback from field experts confirms that CAMM has a well-designed structure and is easy to comprehend. Based on our model, the crytographic agility of an IT landscape can be systematically measured and improved step by step. We expect that this will enable companies and to respond better and faster to threats resulting from broken cryptographic schemes. This work serves to promote CAMM and encourage others to apply it in practice and develop it jointly.