Trusted Computing

Computer security is undeniably important, and as new vulnerabilities are discovered and exploited, the perceived need for security solutions grows' [1]. As things stand today, neither the computer user nor a communicating party can trust much about a personal computer, despite numerous attempts made to enhance security.
If computer hardware is accessible, then there are a variety of ways to modify the operating system (OS) and installed applications. Even if the physical security of the hardware is guaranteed, many means of compromising system integrity remain. Current OSs and applications are highly complex, thereby making it almost impossible to remove all vulnerabilities. In conjunction with this, users can easily run malicious software capable of damaging the system's integrity.
As the use of personal computing devices, be they PCs, PDAs, mobile phones or broadcast receivers, becomes increasingly widespread, they may be used for administering bank accounts, performing e-commerce transactions or managing personal information, all of which require the user to trust the personal device. In combination with this, there are a variety of reasons why a communicating party may need to trust a remote device; for example, the third party may be a bank where the remote device is being used for e-commerce, the third party may be a content provider where the remote device is performing digital rights management (DRM) or the remote device may be performing other security functions, such as authentication or key management, on behalf of third party.
Various approaches to...