<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Blog of Trust &#187; TNC</title>
	<atom:link href="http://blogoftrust.com/category/tnc/feed" rel="self" type="application/rss+xml" />
	<link>http://blogoftrust.com</link>
	<description>Watching the trusted computing world</description>
	<lastBuildDate>Thu, 17 Feb 2011 14:40:00 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Report from TNC PlugFest</title>
		<link>http://blogoftrust.com/report-from-tnc-plugfest/584</link>
		<comments>http://blogoftrust.com/report-from-tnc-plugfest/584#comments</comments>
		<pubDate>Thu, 02 Dec 2010 16:58:20 +0000</pubDate>
		<dc:creator>Ken Y-N</dc:creator>
				<category><![CDATA[TNC]]></category>
		<category><![CDATA[if-map]]></category>
		<category><![CDATA[plugfest]]></category>

		<guid isPermaLink="false">http://blogoftrust.com/report-from-tnc-plugfest/584</guid>
		<description><![CDATA[Lisa Lorenzin from Juniper Networks posted to the official Trusted Computing Group blog regarding the recent TNC PlugFest focusing on TNC IF-MAP Binding for SOAP. I&#8217;ve heard about these bi-annual events before, and they do seem like a lot of hard work but fun! It mentions that Open Source projects also participated, but it didn&#8217;t [...]]]></description>
			<content:encoded><![CDATA[<p>Lisa Lorenzin from Juniper Networks posted to the official Trusted Computing Group blog regarding the <a title="TNC Members Hold Successful Plugfest" href="http://www.trustedcomputinggroup.org/community/2010/11/tnc_members_hold_successful_plugfest">recent TNC PlugFest</a> focusing on TNC IF-MAP Binding for SOAP. I&#8217;ve heard about these bi-annual events before, and they do seem like a lot of hard work but fun! It mentions that Open Source projects also participated, but it didn&#8217;t note that qualifying Open Source projects can, subject to various not-too-onerous restrictions, get certified for free.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogoftrust.com/report-from-tnc-plugfest/584/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Steve Hanna on military-grade network attacks in India</title>
		<link>http://blogoftrust.com/steve-hanna-on-military-grade-network-attacks-in-india/573</link>
		<comments>http://blogoftrust.com/steve-hanna-on-military-grade-network-attacks-in-india/573#comments</comments>
		<pubDate>Fri, 08 Oct 2010 16:39:12 +0000</pubDate>
		<dc:creator>Ken Y-N</dc:creator>
				<category><![CDATA[TNC]]></category>
		<category><![CDATA[india]]></category>
		<category><![CDATA[steve hanna]]></category>

		<guid isPermaLink="false">http://blogoftrust.com/steve-hanna-on-military-grade-network-attacks-in-india/573</guid>
		<description><![CDATA[CyberMedia India Online recently published an interesting interview with Steve Hanna of Juniper Networks (he&#8217;s co-chair of the Trusted Network Connect working group, not the whole TCG as noted in the article!) on cyber attacks in India. India is an interesting case as they are being attacked by foreign governments, or at least groups funded [...]]]></description>
			<content:encoded><![CDATA[<p>CyberMedia India Online recently published an interesting interview with Steve Hanna of Juniper Networks (he&#8217;s co-chair of the Trusted Network Connect working group, not the whole TCG as noted in the article!) on <a title="Commercial enterprises, governments are not able to countering military-grade attacks as we have designed our defenses as per the threat landscape five years ago" href="http://www.ciol.com/Technology/Security/Interviews/Signature-based-security-approaches-not-enough/141930/0/">cyber attacks in India</a>.</p>
<p>India is an interesting case as they are being attacked by foreign governments, or at least groups funded by them, so the need for military-grade defences is present not just for governmental concerns, but business too, which is where the Trusted Platform Module and related techniques come in. As Steve Hanna says:</p>
<blockquote><p>So we need to have military-grade defense even in commercial places. Otherwise the APT [<em>Advanced Persistent Threats</em>] can creep into organizations and infect the systems. And generally it is very difficult to disinfect the machines later.</p>
</blockquote>
]]></content:encoded>
			<wfw:commentRss>http://blogoftrust.com/steve-hanna-on-military-grade-network-attacks-in-india/573/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TNC and SCAP Triumfantly wed</title>
		<link>http://blogoftrust.com/tnc-and-scap-triumfantly-wed/571</link>
		<comments>http://blogoftrust.com/tnc-and-scap-triumfantly-wed/571#comments</comments>
		<pubDate>Sat, 02 Oct 2010 14:24:50 +0000</pubDate>
		<dc:creator>Ken Y-N</dc:creator>
				<category><![CDATA[TNC]]></category>
		<category><![CDATA[scap]]></category>
		<category><![CDATA[triumfant]]></category>

		<guid isPermaLink="false">http://blogoftrust.com/tnc-and-scap-triumfantly-wed/571</guid>
		<description><![CDATA[I&#8217;m a bit baffled by exactly what the benefit is regarding the recent announcement by Triumfant that they have worked with Juniper Networks to integrate TNC into SCAP. I&#8217;ve read the article twice and followed all the links, but I&#8217;m sadly not much the wiser! Perhaps this is the key: It may sound elemental, but [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m a bit baffled by exactly what the benefit is regarding the recent announcement by Triumfant that <a href="http://blog.triumfant.com/2010/09/28/triumfant-and-trusted-network-connect/">they have worked with Juniper Networks to integrate TNC into SCAP</a>. I&#8217;ve read the article twice and followed all the links, but I&#8217;m sadly not much the wiser! Perhaps this is the key:</p>
<blockquote><p>It may sound elemental, but implementing TNC implies that an organization must have some common minimum security criteria to apply, which surprisingly is not always the case.&#160; This is where the integration with SCAP was so natural, as SCAP provides a standard set of criteria that is well defined and readily applicable to the TNC process.</p>
</blockquote>
<p>I think it means that SCAP defines a collection of TNC rules (or a collection of TNC rules define a SCAP level), and Triumfant provide policies that describe the SCAP criteria, and their systems ensure that the policies are always enforced.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogoftrust.com/tnc-and-scap-triumfantly-wed/571/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Why IF-MAP v2.0 is important</title>
		<link>http://blogoftrust.com/why-if-map-v2-0-is-important/570</link>
		<comments>http://blogoftrust.com/why-if-map-v2-0-is-important/570#comments</comments>
		<pubDate>Sat, 02 Oct 2010 14:06:45 +0000</pubDate>
		<dc:creator>Ken Y-N</dc:creator>
				<category><![CDATA[TNC]]></category>
		<category><![CDATA[if-map]]></category>

		<guid isPermaLink="false">http://blogoftrust.com/why-if-map-v2-0-is-important/570</guid>
		<description><![CDATA[There&#8217;s been an update to the Trusted Network Connect workgroup&#8217;s IF-MAP (Interface for Metadata Access Points) protocol to add a new notify feature, according to a post on the official Trusted Computing Group blog. Some of the things being done with the specification are integrating network authentication with physical presence, tracking IT assets, and integrating [...]]]></description>
			<content:encoded><![CDATA[<p>There&#8217;s been an update to the Trusted Network Connect workgroup&#8217;s IF-MAP (Interface for Metadata Access Points) protocol to add a new notify feature, according to a <a title="Mapping the Way to Integrated Security" href="http://www.trustedcomputinggroup.org/community/2010/09/mapping_the_way_to_integrated_security">post on the official Trusted Computing Group blog</a>.</p>
<p> Some of the things being done with the specification are integrating network authentication with physical presence, tracking IT assets, and integrating legacy SCADA systems into the corporate network.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogoftrust.com/why-if-map-v2-0-is-important/570/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Trusted Multi-Tenant Infrastructure Work Group</title>
		<link>http://blogoftrust.com/the-trusted-multi-tenant-infrastructure-work-group/561</link>
		<comments>http://blogoftrust.com/the-trusted-multi-tenant-infrastructure-work-group/561#comments</comments>
		<pubDate>Mon, 27 Sep 2010 15:42:30 +0000</pubDate>
		<dc:creator>Ken Y-N</dc:creator>
				<category><![CDATA[TCG]]></category>
		<category><![CDATA[TNC]]></category>
		<category><![CDATA[Virtualisation]]></category>
		<category><![CDATA[cloud]]></category>
		<category><![CDATA[if-map]]></category>
		<category><![CDATA[trusted multi-tenant]]></category>

		<guid isPermaLink="false">http://blogoftrust.com/the-trusted-multi-tenant-infrastructure-work-group/561</guid>
		<description><![CDATA[Sorry I&#8217;m a bit slow with the news, but the Trusted Computing Group&#8217;s Trusted Multi-Tenant Infrastructure Work Group (that&#8217;s longhand for Cloud Security, basically) has now publically launched! The TCG has also published a white paper on Cloud Computing and Security &#8211; A Natural Match, that discusses why you want a TPM in the cloud, [...]]]></description>
			<content:encoded><![CDATA[<p>Sorry I&#8217;m a bit slow with the news, but the Trusted Computing Group&#8217;s Trusted Multi-Tenant Infrastructure Work Group (that&#8217;s longhand for <a href="http://www.trustedcomputinggroup.org/solutions/cloud_security">Cloud Security</a>, basically) has <a href="http://www.networkworld.com/news/2010/091310-trusted-computing-group-cloud-security.html">now publically launched</a>!</p>
<p>The TCG has also published a white paper on <a href="http://www.trustedcomputinggroup.org/resources/cloud_computing_and_security__a_natural_match">Cloud Computing and Security &#8211; A Natural Match</a>, that discusses why you want a TPM in the cloud, and there has also been <a href="http://www.businesswire.com/news/home/20100913005373/en/Trusted-Computing-Group-TCG-Extends-Trust-Based-Security">an extension to the IF-MAP protocol for Trusted Network Connect</a> to support the Trusted Multi-Tenant Infrastructure Work Group.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogoftrust.com/the-trusted-multi-tenant-infrastructure-work-group/561/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IF-Map is Facebook for endpoint devices</title>
		<link>http://blogoftrust.com/if-map-is-facebook-for-endpoint-devices/546</link>
		<comments>http://blogoftrust.com/if-map-is-facebook-for-endpoint-devices/546#comments</comments>
		<pubDate>Sun, 01 Aug 2010 15:51:03 +0000</pubDate>
		<dc:creator>Ken Y-N</dc:creator>
				<category><![CDATA[TNC]]></category>
		<category><![CDATA[george lawton]]></category>
		<category><![CDATA[if-map]]></category>

		<guid isPermaLink="false">http://blogoftrust.com/if-map-is-facebook-for-endpoint-devices/546</guid>
		<description><![CDATA[An interesting article on the Trusted Computing Group’s (TCG) Infrastructure-Metadata Access Point (IF-MAP) specification has the curious quote that I have used as the title for this article: &#34;IF-Map is Facebook for endpoint devices,&#34; said Matt Webster, product management director at Lumeta and cochair of TCG&#8217;s Trusted Network Connect (TNC) workgroup, which developed the IF-MAP [...]]]></description>
			<content:encoded><![CDATA[<p><a title="New Protocol Improves Interaction among Networked Devices and Applications" href="http://www.computer.org/portal/web/computingnow/archive/news065">An interesting article</a> on the Trusted Computing Group’s (TCG) Infrastructure-Metadata Access Point (IF-MAP) specification has the curious quote that I have used as the title for this article:</p>
<blockquote><p>&quot;IF-Map is Facebook for endpoint devices,&quot; said Matt Webster, product management director at Lumeta and cochair of TCG&#8217;s Trusted Network Connect (TNC) workgroup, which developed the IF-MAP specification.</p>
</blockquote>
<p>I&#8217;m not really sure how well that analogy works for me – if IF-MAP is Facebook, then what is <a href="http://www.facebook.com/pages/I-Hate-Farmville/131390668240">Farmville</a>? – but regardless, the rest of the article is a good read.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogoftrust.com/if-map-is-facebook-for-endpoint-devices/546/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TNC certification program announced</title>
		<link>http://blogoftrust.com/tnc-certification-program-announced/521</link>
		<comments>http://blogoftrust.com/tnc-certification-program-announced/521#comments</comments>
		<pubDate>Fri, 30 Apr 2010 16:42:11 +0000</pubDate>
		<dc:creator>Ken Y-N</dc:creator>
				<category><![CDATA[TNC]]></category>
		<category><![CDATA[juniper]]></category>
		<category><![CDATA[tnc@fhh]]></category>

		<guid isPermaLink="false">http://blogoftrust.com/tnc-certification-program-announced/521</guid>
		<description><![CDATA[The official Trusted Computing Group blog recently announced that the certification program for Trusted Network Connect is now up and running. The first products to get certified are two devices from Juniper Networks and the TNC@FHH open source implementation of the TNC protocol. I think it&#8217;s great from not just a purely technical viewpoint that [...]]]></description>
			<content:encoded><![CDATA[<p>The official Trusted Computing Group blog recently announced that the <a title="TNC Certified: Network Security You Can Count On" href="http://www.trustedcomputinggroup.org/community/2010/04/tnc_certified_network_security_you_can_count_on">certification program for Trusted Network Connect is now up and running</a>. The first products to get certified are two devices from Juniper Networks and the <a href="http://trust.inform.fh-hannover.de/">TNC@FHH</a> open source implementation of the TNC protocol. I think it&#8217;s great from not just a purely technical viewpoint that an open source implementation has been certified, but it&#8217;s also an important PR plus point for the TCG to show that Trusted Computing and Open Source are not mutually incompatible concepts.</p>
<p>Please read the <a href="http://www.trustedcomputinggroup.org/community/2010/04/tnc_certified_network_security_you_can_count_on">original article</a> for the full story.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogoftrust.com/tnc-certification-program-announced/521/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TNC&#8217;s latest plugfest report</title>
		<link>http://blogoftrust.com/tncs-latest-plugfest-report/516</link>
		<comments>http://blogoftrust.com/tncs-latest-plugfest-report/516#comments</comments>
		<pubDate>Wed, 21 Apr 2010 16:20:34 +0000</pubDate>
		<dc:creator>Ken Y-N</dc:creator>
				<category><![CDATA[TNC]]></category>
		<category><![CDATA[plugfest]]></category>

		<guid isPermaLink="false">http://blogoftrust.com/tncs-latest-plugfest-report/516</guid>
		<description><![CDATA[The Trusted Computing Group&#8217;s Trusted Network Connect working group held their fifth annual plugfest, where fourteen TNC implementations were tested over three days to see how well they played together. Read the linked full report on the TCG web site to see how they all got on.]]></description>
			<content:encoded><![CDATA[<p>The Trusted Computing Group&#8217;s Trusted Network Connect working group held their fifth annual plugfest, where <a title="TCG Interoperability Fun – Lots of Diet Coke, Some Late Nights and a Few Flashing Lights" href="http://www.trustedcomputinggroup.org/community/2010/04/tcg_interoperability_fun__lots_of_diet_coke_some_late_nights_and_a_few_flashing_lights">fourteen TNC implementations were tested over three days</a> to see how well they played together. Read the linked full report on the TCG web site to see how they all got on.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogoftrust.com/tncs-latest-plugfest-report/516/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NAC, virtualisation and cloud security</title>
		<link>http://blogoftrust.com/nac-virtualisation-and-cloud-security/514</link>
		<comments>http://blogoftrust.com/nac-virtualisation-and-cloud-security/514#comments</comments>
		<pubDate>Wed, 14 Apr 2010 15:57:20 +0000</pubDate>
		<dc:creator>Ken Y-N</dc:creator>
				<category><![CDATA[TNC]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[nac]]></category>
		<category><![CDATA[network world]]></category>

		<guid isPermaLink="false">http://blogoftrust.com/nac-virtualisation-and-cloud-security/514</guid>
		<description><![CDATA[Network World recently published an article by Andreas M. Antonopoulos looking at how security works (or doesn&#8217;t) in the cloud. The basis will be NAC, Network Access Control, as: With NAC you have endpoints (laptops, smartphones, desktops, printers) connecting to switches ad-hoc and in a transient fashion. Security must be coordinated between the stuff that [...]]]></description>
			<content:encoded><![CDATA[<p>Network World recently published an article by Andreas M. Antonopoulos looking at <a title="Virtualization and cloud security modeled on NAC" href="http://www.networkworld.com/columnists/2010/041210antonopoulos.html">how security works (or doesn&#8217;t) in the cloud</a>.</p>
<p>The basis will be NAC, Network Access Control, as:</p>
<blockquote><p>With NAC you have endpoints (laptops, smartphones, desktops, printers) connecting to switches ad-hoc and in a transient fashion. Security must be coordinated between the stuff that runs on the endpoint (antivirus, policies and so on) and the stuff that needs to run in the network (firewalls, intrusion detection/prevention) while applying policies dynamically as each endpoint &quot;arrives on the scene&quot;.</p>
</blockquote>
<p>His NAC solution of choice is that from the Trusted Computing Group&#8217;s Trusted Network Connect architecture, which he reckons is a good fit for virtualisation and The Cloud in general.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogoftrust.com/nac-virtualisation-and-cloud-security/514/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Video: Steve Hanna at Interop Mumbai 2009</title>
		<link>http://blogoftrust.com/video-steve-hanna-at-interop-mumbai-2009/507</link>
		<comments>http://blogoftrust.com/video-steve-hanna-at-interop-mumbai-2009/507#comments</comments>
		<pubDate>Fri, 26 Mar 2010 17:19:00 +0000</pubDate>
		<dc:creator>Ken Y-N</dc:creator>
				<category><![CDATA[TNC]]></category>
		<category><![CDATA[interop]]></category>
		<category><![CDATA[mumbai]]></category>

		<guid isPermaLink="false">http://blogoftrust.com/video-steve-hanna-at-interop-mumbai-2009/507</guid>
		<description><![CDATA[I seem to be coming across a lot of video recently, so here is Steve Hanna doing a keynote at Interop Mumbai 2009 on Coordinated Security: A New Paradigm. I got the link from Fix Internet Problems, but I&#8217;ll directly inline the five-part YouTube videos into the post.]]></description>
			<content:encoded><![CDATA[<p>I seem to be coming across a lot of video recently, so here is Steve Hanna doing a keynote at Interop Mumbai 2009 on Coordinated Security: A New Paradigm. I got the link from <a title="Interop Mumbai 2009: Keynote by Steve Hanna" href="http://fix-internet-problem.com/internet-security-problem/interop-mumbai-2009-keynote-by-steve-hanna-part-1-of-5">Fix Internet Problems</a>, but I&#8217;ll directly inline the five-part YouTube videos into the post.</p>
<div style="padding-bottom: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: none; padding-top: 0px" id="scid:5737277B-5D6D-4f48-ABFC-DD9C333F4C5D:9b361519-1f32-432e-8cd2-183991a2922f" class="wlWriterEditableSmartContent">
<div><object width="425" height="355"><param name="movie" value="http://www.youtube.com/v/k0KIZ_WDIrA&amp;hl=en_GB&amp;fs=1&amp;&amp;hl=en"></param><embed src="http://www.youtube.com/v/k0KIZ_WDIrA&amp;hl=en_GB&amp;fs=1&amp;&amp;hl=en" type="application/x-shockwave-flash" width="425" height="355"></embed></object></div>
</div>
<div style="padding-bottom: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: none; padding-top: 0px" id="scid:5737277B-5D6D-4f48-ABFC-DD9C333F4C5D:2b8ed952-69bb-4d8b-9ec6-0f7f344a16d3" class="wlWriterEditableSmartContent">
<div><object width="425" height="355"><param name="movie" value="http://www.youtube.com/v/mE97a8Pc_mE&amp;hl=en"></param><embed src="http://www.youtube.com/v/mE97a8Pc_mE&amp;hl=en" type="application/x-shockwave-flash" width="425" height="355"></embed></object></div>
</div>
<div style="padding-bottom: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: none; padding-top: 0px" id="scid:5737277B-5D6D-4f48-ABFC-DD9C333F4C5D:81fd35e2-6696-4326-8fab-9f87dacf3da2" class="wlWriterEditableSmartContent">
<div><object width="425" height="355"><param name="movie" value="http://www.youtube.com/v/-cLUq3gnAVs&amp;hl=en_GB&amp;fs=1&amp;&amp;hl=en"></param><embed src="http://www.youtube.com/v/-cLUq3gnAVs&amp;hl=en_GB&amp;fs=1&amp;&amp;hl=en" type="application/x-shockwave-flash" width="425" height="355"></embed></object></div>
</div>
<div style="padding-bottom: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: none; padding-top: 0px" id="scid:5737277B-5D6D-4f48-ABFC-DD9C333F4C5D:e4f54b0c-33bb-4264-856d-f3f4be737193" class="wlWriterEditableSmartContent">
<div><object width="425" height="355"><param name="movie" value="http://www.youtube.com/v/TP-nrUA1acQ&amp;hl=en_GB&amp;fs=1&amp;&amp;hl=en"></param><embed src="http://www.youtube.com/v/TP-nrUA1acQ&amp;hl=en_GB&amp;fs=1&amp;&amp;hl=en" type="application/x-shockwave-flash" width="425" height="355"></embed></object></div>
</div>
<div style="padding-bottom: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: none; padding-top: 0px" id="scid:5737277B-5D6D-4f48-ABFC-DD9C333F4C5D:bacb495c-2d7d-4c69-ae38-c02272556508" class="wlWriterEditableSmartContent">
<div><object width="425" height="355"><param name="movie" value="http://www.youtube.com/v/D67MbXB2U04&amp;hl=en_GB&amp;fs=1&amp;&amp;hl=en"></param><embed src="http://www.youtube.com/v/D67MbXB2U04&amp;hl=en_GB&amp;fs=1&amp;&amp;hl=en" type="application/x-shockwave-flash" width="425" height="355"></embed></object></div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://blogoftrust.com/video-steve-hanna-at-interop-mumbai-2009/507/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

