Tuesday, April 28, 2020

Kadeejah Johnson Essays (496 words) - Neuropsychological Assessment

Kadeejah Johnson Education 201 Professor A. Baker April 29, 2016 Chapter 15: Physical and Cognitive Development in Middle Adulthood Chapter 15: Apply (page 406) Between ages 40 and 50, Nancy gained 20 pounds. She also began to have trouble opening tightly closed jars, and her calf muscles ached after climbing a flight of stairs "Exchanging muscle for fat must be an ine vitable part of aging, "Nancy thought, is she correct? Why or why not? She is correct because the rise in fat largely affects the torso and occurs as fatty deposits within the body cavity; as fat beneath the skin on the limbs declines. On average, size of the abdomen increases 7 to 14 percent. Women tend to have a large portion due to weight gain, age-related changes in muscle-fat makeup also contribute. In the forties and fif ties muscle mass declines very gradually, which is largely due to atrophy of fast-twitch fibers, which are responsible for speed and explosive strength. Chapter 15: Reflect (page 412) Which midlife health problem is of greatest personal concern to you? What steps can you take now to help prevent it? I was having trouble getting up in the mornings and seemed to have less energy than most people my age. Some of my friends started to make comment s about my weight . They tried to make them in a teasing way, but my feel ings were hurt. I tried to tell myself that I didn't have a problem because I went to work every day and took care of my f amily. I felt I was a social eater, and that I didn't have an out of control issue . Finally, I decided that I needed to do something about my weight . I asked my doctor where to get help. I got the help I needed and now feel very proud of myself for takin g control of my eating and wiegh t . Chapter 15: Review (419) How do slowing of cognitive processing, reduced working-memory capacity, and difficulties with inhibition affect memory in midlife? What can older adults do to compensate for these declines? In many ways, our memories shape who we are. They ma ke up our internal biographies the stories we tell ourselves about what we've done with our lives. Our memories tell us who we're connected to, who we've touched during our lives, and who has touched us. In short, our memories are crucial to the essence of who we are as human beings. Memory loss also affects the practical side of life. Remembering how to get from your house to the grocery store or how to do the tasks that make up your job allows you to take care of your needs. That's what makes dementia so scary losing your memory means both losing your ability to live independently and not being able to remember your past experiences.

Thursday, March 19, 2020

Rome city pros and cons essays

Rome city pros and cons essays Rome, as any society, suffered from imperfection. The city experienced some of the greatest architecture, art, entertainment, and trade, however it suffered from many wars, poverty, and cruelty. It was a city of extremes. Even through hardships the Ancient city of Rome achieved sophistication and opportunities. Rome, considered a city of great services and entertainment. Rome, not like most cities, supplied running water to its residents through aqueducts. Romes popularity and city-paved roads allowed it to be a successful city for trade. The baths in Rome were open to all the public. Lucian commented On entering [the baths], one is received into a public hall of good size, with ample accommodation for servants and attendants. The rich and poor both enjoyed the lavish baths. Not to be forgotten, the population suffering from poverty was provided with free bread and entertainment. As Fronto states The emperors were very careful not to neglect the basic needs of the inhabitants of Rome. They enjoyed the free views of gladiatorial games and the most popular chariot races in the Circus Maximus, holding about a fourth of Romes population. The gladiatorial combats helped control Romes population and punished those who had committed crimes. The Bread and Circuses allowed peace to exist in the ci ty. Rome offered the aristocratic people much more than its common people. Juvenal states In a word, in Rome everything costs money; It takes great wealth to sleep in the city. Much of the Roman population lived in poverty suffering of hunger and unsanitary conditions. The streets were not only filthy, but dangerous. Chamber pots of human waste and objects such as utensils would often be thrown out of windows onto the people, injuring many. Baths were not a luxury to those who lived nearby having to hear the loud, obnoxious sounds of its users. The entertainments including gladiat...

Tuesday, March 3, 2020

Define and write your professional learning and development identity

Define and write your professional learning and development identity Write your professional identity, Training Journal Its not an accident that one of the West Ends most popular stage shows at the moment is about a character in search of his purpose. The protagonist in Avenue Q is a comedy puppet searching for direction. But his questions of Who am I? and What am I here to do? are not just New Age, mystical musings; they are at the core of what it means to be successful in any business. In fact, if you scratch the surface of most successful companies, youll find whole departments set up to create a brand identity that lets customers know exactly who they are and what they do. Take the brand Innocent Drinks, for example. If you buy an Innocent smoothie, youre not just buying a drink. Youre buying a fun, fresh and completely natural experience that contains two of servings of fruit in a 250ml serving. Its a tasty little shot of good health. And the witty words on the Innocent website, bottles and advertising campaigns tell you so. But its not just companies that need to create this type of brand identity. You need to forge your own voice within your organisation. The employees you work with need to know who you are; what you stand for; what you do and why they need to take notice of you and your work. Communicating this in a powerful, succinct way isnt always easy. Employees often get caught up in the ins and outs of their particular roles and forget about issues outside their immediate remit. They may even feel that taking time out for professional development is an unwelcome diversion from the work at hand. For this reason its essential that you as a learning and development specialist develop a strong professional identity to enable you to have greater influence over the people you work with. Your skills, personality and values are integral to your brand. But its also vital to develop a strong, human, written voice to ensure that you present yourself in a positive light. Innocent have cottoned on to the fact that creating a distinct written voice is an effective way of connecting with their customers. You also need to ensure that your writing style is an integral part of your personal brand. Your written voice is the end result of the words and phrases you use in order to communicate your ideas and recommendations. It needs to be bright, concise and speak directly to your reader. But it should also reflect your personality, vision, achievements and goals. So here is a blueprint for creating a written voice that is distinctly yours. Laying the foundations You need to do some groundwork before working on your writing style. Grab a pen and paper and jot down words, phrases and sentences that describe your skills and personality. You might write, I am someone who sees potential in others, or My core skills are motivating and empowering others. Spend time thinking about your values and all the facets of your personality that make you who you are. And dont forget to note down examples of the value that you create for your organisation. Next, decide which points are most relevant to your work. Organise these into the headings values, personality traits, skills and results. Finally, combine all of this into a powerful statement of purpose. Decide what the overall purpose of your job is. And make sure that this is aligned with the purpose of your organisation. Remember, this foundation work is integral to creating the brand that you will express through your written voice. So dont feel that this has to be a one-off exercise. You can keep coming back to this until you feel youve completely brainstormed everything about you and your work. And keep this work safe its a powerful document that you should keep referring to. Sizzling sound bites In order to create a strong professional identity through your writing, you need to develop ways of succinctly communicating important information about you and your work. Imagine that youre in an airport when you meet a powerful business leader, such as Richard Branson. You strike up a brief conversation and he asks you what you do for a living. You have about 30 seconds to impress before you go your separate ways. Most people would say something such as, Im a learning and development manager for a large pharmaceutical company. But describing yourself in terms of your job title and company doesnt give you a strong identity. Throughout the world there are thousands of learning and development managers in pharmaceutical companies. So set yourself apart by communicating whats special about your brand of learning and development. The way to do this is to explain the context of your role, the issues you deal with and your results. For instance, you could say, I help pharmaceutical research teams to increase their productivity. I do this by transforming the way they approach their work. By finding out what makes them tick, I help each person add more to the business bottom line. Now it probably wouldnt sound natural to deliver this statement in its entirety in one go. But if you have it committed to memory, youll be able work each of its component sentences into most introductory business conversations. By speaking in this way, you explain who you are, what you do and what value you bring to your organisation. Practise developing these compelling two or three sentence summaries of what you do. Write out several of them, referring to different areas of your work. And begin to use them when people both internally and externally ask you about what you do. What does your writing really say about you? Gather together some recent documents that you have written. These could be reports, briefing documents or even emails that you have sent to other employees. Critically look at what messages your writing sends. For example, if one of the things you most value is clear communication, then look at how clear your writing is. If your purpose is to make other peoples jobs more efficient, is your writing clearly structured so that its quick and easy to read? And do you refer to psychometric models or training processes that only a training specialist would really grasp? Does your writing really reflect your values and personality? If you tend to use lots of long sentences, your writing may not reflect a decisive personality. Similarly, a long document that lacks subheads to break it up is not the best way to reflect that youre excited by change. Your writing needs to communicate your brand the elements that make you different. If it doesnt effectively communicate the changes that you have made happen, then it wont be representing you and your work. The principles behind the following techniques can help you to analyse your current documents. Applying them to any new written work can transform the way you (and your documents) are perceived. And crucially, they can help you to effectively communicate the underlying purpose of your work. Seven techniques for honing your written voice One Focus on your reader Before you begin writing a document, ask yourself the following questions: What is the document about? Who will read it? How much do they already know about the subject? What do they absolutely need to know? How important is the subject to them? How interested are they in the subject (which is not necessarily the same question as above)? Focusing on your readers in this way will help to make sure that you present yourself as helping their work lives. Training may be top of your agenda but others may not see it as a business priority. Thinking about the needs of your readers will help you shape your writing so that its relevant to them. Two Clarify your main message If youre unsure of your main message, you can be certain that your readers will be equally bemused. So spend time thinking about what you really want to say. Brainstorm ideas by asking yourself the questions: What? Where? When? How? Why? and Who? Group together the points or ideas that have things in common. Then decide what is important and essential for your readers to know. Your main message is among these points and it can vary depending on which stance you want to take. For example, if youre writing a report on psychometric testing as a training tool, your main message might be to outline the cost savings to your organisation. Alternatively, you may want to stress how employees work better as a team once they become aware of their own personality traits. Next you need to plan which order to put your points in. Your main message is the golden nugget of any document. So make sure it stands out by including it in the first paragraph. Then arrange your other points in order of importance. Three Create snappy titles and subheads Journalists know that a headline is the most powerful tool for winning over a reader. So take a tip from professional writers and make yours arresting. If your report is about the cost savings of psychometric testing, your title could be Psychometric testing: how a fifty-minute quiz has saved 50,000. This is much more powerful than a functional title, such as The results of workplace psychometric testing Similarly, break up the text with subheads that are equally attention-grabbing. For example, if youre writing about an initiative that will be happening shortly, you could include a subhead that reads The final countdown. This creates an image of the initiative as being exciting and worth waiting for. Four Keep it short and sweet Short sentences are effective as they break up ideas into bite-size chunks. Aim for each sentence to be between 15 and 20 words. If your sentences are any longer, its difficult for your ideas to stand out. Similarly, never write a 1000-word document when a 500-word one will do. Always go through your work and cross out any meaningless words or sentences. And aim to make every single word count. Its better to do several drafts of a document than to rush out the original long, rambling version. Five Use active language Use the active voice where possible, as it gives your writing movement. For instance, write This technique has really improved productivity, instead of A real improvement in the productivity of employees has been noticed following the application of this simple technique. Notice that the first example uses the verb improve rather than the noun improvement. Opting to use verbs over nouns helps to make your writing punchier. Six Share your success For any training programme to be a success, it needs to address core business needs or goals. Ask yourself why your organisation exists, why it matters and what difference it makes in peoples lives. Always communicate the success of any learning and development initiatives in terms of specific business objectives. For example, you can write Performance management training reduced staff turnover by 5 per cent in 2009, saving 100,000. By sharing specific business results in this way, you enable others to perceive your initiatives as having true value and being dynamic enough to improve the business bottom line Seven Be accurate To gain credibility, your writing needs to be flawless. So pay particular attention to grammar, punctuation and spelling. When youve worked long and hard on a document, it can be easy to gloss over typos and other mistakes as your eyes begin to see what they expect to see. For this reason, you need to proofread documents very slowly. It helps to take a pencil and stop it at every word. Always double check facts and figures, and if possible, also ask a colleague to proofread it too. A fresh pair of eyes can work wonders. Make your own writing a focus at the outset of any new initiatives and training programmes. And ensure that you apply your new written voice consistently. It is well worth the effort, as a strong written voice is an ambassador for all you do. Remember, in these troubled economic times, excelling in all areas of your personal brand is a must. And using language effectively can propel you to the next tier of success. Whats more, mastering writing skills not only helps to cement your own professional identity, but it can inspire your colleagues to do the same. Leave others in no doubt about who you are and what youre here to do, and theyll be more likely to follow your lead.

Sunday, February 16, 2020

HR Essay Example | Topics and Well Written Essays - 1250 words - 1

HR - Essay Example This is because according to Westphal and Fredickson (2001), management is a complex phenomenon that entails both an art and a science, revolving round the utilization of human resource and human capital to achieving organizational goals. As an art, management can be said to be the practice of making people more effective than they would naturally be in the absence of any management in place (Tushman and Nadler, 2009). Meanwhile, the twenty-first century has become a very challenging and competitive century for all organizations, businesses and companies to be more effective (Armstrong and Overton, 2007). The need for competitiveness is because the world is now a global village and so any company operating in any part of the world finds itself competing with all other companies in the same industry (Argyris and Schon DA. 1996). With such kind of competition, the best way to ensure survival is through the maximization of human resource, which the definition makes clear, can only be ac hieved through management. What is more, the science in management has been said to manifest in the various ways in which management is performed. In this regard also, it would be said that the twenty-first century comes with so much opportunities for leaders to be highly dynamic in the science of management, consolidating the continual growth of management. Why management will not die anytime soon Generally, management will not die anytime soon in the twenty-first century as Koch & Godden (1996) claim because the principles and pillars on which management strives continue to be important and even more important in the twenty-first century than they were before. These four pillars have been identified by Tushman and Nadler (2009) as being planning, organizations, directing and monitoring. Van (2006) notes that planning is the process of identifying what an organization would need in the short to long term basis and putting in place structures to ensure that those needs are met, whil es identifying the cost and benefits that will come with achieving those goals. Generally, proper planning has been said to prevent poor performance. The debate that management will die soon in the

Sunday, February 2, 2020

The Use of Force by Police, Specific Cases and their Implications Research Paper

The Use of Force by Police, Specific Cases and their Implications - Research Paper Example Force is used by the police to overcome resistance to their authority and to protect both civilians and officers. It is necessary that they have this ability in order for them to carry out their function, and the use of reasonable force is legal. However, the subject is one of significant contention, in regards to both non-deadly and deadly force. The use of force is often connected with racism, with significant concern by civilians that many instances where force is used are the result of racial profiling. There is rising debate about whether the police overstep their boundaries in the use of force, using force when it is not necessary, and in order to subdue or suppress civilians that are involved in undesirable, but not illegal actions. Examples of this include use of police force on civilians during peaceful protests, and using excessive force on particular races but not others. This had lead to concerns that control surrounding the use of force in the police is severely lacking. The manner in which police use force is varied and depends on the circumstance, the individuals involved and the agency in which the officer is from. The most basic form of force involves the use of handcuffs. Other non-lethal forms of force include the use of conductive energy devices (CEDs) such as tasers, and of aerosol sprays such as Oleoresin Capsicum (OC) spray, also known as pepper spray (MacDonald et al., 2009). . Firearms are also used, although the rate at which they are discharged is low, with one study estimating at in 0.6% of incidents a firearm was discharged . There are no national laws or regulations that control the use of firearms within the police, and as a consequence, policies differ between cities and states. The rules and directives concerning the use of force differ between agencies. Within the United States, 45% of local and state law enforcement agencies have been found to allow the use of OC spray, and 20-30% allow the use of CEDs to bypass passive resistan ce . Likewise, different agencies and states have different follow-up procedures for the use of force. The amount of force used by police has been found to differ significantly depending on the authority of the police officer. Detectives were found to be considerably more forceful than patrol officers under the same types of situations . Concern for the use of force by the police is partially connected to the lack of discipline for police officers that use force that is greater than the situation requires, even when the force that was used was clearly unjustified. In the case of the use of lethal force through firearms, following incidents it is often unclear whether the force used was unjustified or justified. As the cases are reviewed by the police, there are few cases where the use of force is considered unjustified and as a consequence there are few criminal charges laid . The definition of justified force that is used by the police in these investigations does not always match this

Saturday, January 25, 2020

Trusted Platform Module (TPM)

Trusted Platform Module (TPM) Trusted Platform Module (TPM) is a term used to define a chip or microcontroller. This chip or microcontroller can be placed into a motherboard configuration such as devices like mobile devices, or a personal computer (PCs). The requirements and application was presented and established by the Trusted Computing Group (TCG), to deliver a solution where a reliable and genuine relationship exists amongst hardware and software configurations. This facility was executed through cryptographic and hashing algorithms. Additional, TPM offers remote confirmation, a verification and authentication process for other third party software. TPM is a global standard for a protected crypto processor, which is a devoted microcontroller or chip intended to protect hardware by joining cryptographic keys into devices. TPMs technical requirements were established and written by TCG and launched in 2003. TCG was created as a nonprofit from inception and known to have brands like Microsoft, IBM, Intel, and Hewlett-Packard as clients. TPM just as well as others has flaws, and suffers from attacks. These attacks include offline dictionary and OIAP attacks; nevertheless, when joined with other endpoint control systems like multifactor authentication, network access control, and malware detection, TPMs contribution to a sound security platform is valid. (Sparks, 2007) This survey is a complete review of research conducted on TPM, its components, mechanisms, application, and authorization protocols. Furthermore, a description of some common attacks to which TPM has been a victim will be presented. Finally, more recent and future implementations will be discussed, such as the incorporation of TPM within mobile and smart devices and even within cloud computing. First, it is important to start with an overview of the TPM specification, its components, and its purpose. The TPM background section discusses in some detail an overarching summary of TPM. This will include what the motivations and advantages are to using TPM as well as how the different types of keys function. Also discussed is the evolution of TPM over time in how it functions in both its hardware encryption but also its capabilities. 2.1 TPM Summary A Trusted Platform Module (TPM) is a cryptographic coprocessor that replaced smart cards in the 1990s and then became present on most commercial personal computer (PCs) and servers. TPMs are almost ubiquitous in computer hardware and typically not seen by users because of the lack of compelling applications that use them. However, this situation has changed effective with TPM version 1.16 by adding the Federal Information Processing Standards (FIPS) bit which is a static flag that verifies if the device or firmware the TPM is attached to is FIPS 140-2 cryptographic module compliant. This compliance is then registered by the consolidated validation certificates granted when FIPS 140-2 is validated and are then registered and published at NIST as public record listed alphabetically by vendor located at http://csrc.nist.gov/groups/STM/cmvp/documents/140-1/1401vend.htm. (TCG FIPS 140-2 Guidance for TPM 2.0, ver 1, rev.8, 2016) Therefore, the line of thinking of TPM has increasingly becom e one of importance and an essential ingredient to cryptographic defense community whom are required to prove their FIPS 140-2 compliance. However, this was not always the case since security was not a mainstream issue in the early years of the Internet. 2.2 Motivation to use TPM The motivation for TPM began decades after the advent of what is known as the Internet. From the creation of Advanced Research Projects Agency (ARPA) in 1969 it took almost nineteen (19) years for us to become aware of the first known exploit called the Internet Worm in 1988. (Pearson Education, Inc., 2014) Until this time the focus had always been on the development of the computer with no security hardware and software that was easy to use. There was a real concept of information security threats. However, in the 1990s there was the concept of the potential of commerce the Internet would have and the need to secure the PCs that would exchange with that commerce. This prompted many computer engineers to convene and form and develop the first TPMs which became known to be as the Trusted Computing Group (TPM: A Brief Introduction, 2015). A main objective of this group was a cost effective approach to create a hardware anchor for PC system security on which secure systems could be buil t. This first resulted in a TPM chip that was required to be attached to a motherboard and the TPM command set was architected to provide all functions necessary for its security use cases. 2.2.1.Evolution TPM has evolved considerably over the years to become the trusted platform it is today. The earlier TPM 1.2 standard was incorporated into billions of PCs, servers, embedded systems, network gear and other devices, the evolving Internet of Things and increasing demand for security beyond traditional PC environment led TCG to develop a new TPM specification, which recently was adopted as an international standard ISO/IEC 11889:2015. For more flexibility of application and to enable more widespread use of the specification, TCG created TPM 2.0 with a library approach. This allows users to choose applicable aspects of TPM functionality for different implementation levels and levels of security. Also, new features and functions were added, such as algorithm agility, the ability to implement new cryptographic algorithms as needed (Trusted Platform Module (TPM): A Brief Introduction, 2015). ISO/IEC 11889-1:2015 ISO/IEC 11889-1:2015 defines the architectural elements of the Trusted Platform Module (TPM), a device which enables trust in computing platforms in general. Some TPM concepts are explained adequately in the context of the TPM itself. Other TPM concepts are explained in the context of how a TPM helps establish trust in a computing platform. When describing how a TPM helps establish trust in a computing platform, ISO/IEC 11889-1:2015 provides some guidance for platform requirements. However, the scope of ISO/IEC 11889 is limited to TPM requirements (Trusted Platform Module (TPM) Summary, 2008). 2.3 TPM Working Functionality The TPM (Trusted Platform Module) is a computer chip (microcontroller) that can securely store artifacts used to authenticate the platform on a PC or laptop. These artifacts can include passwords, certificates, or encryption keys. A TPM can also be used to store platform measurements that help ensure that the platform remains trustworthy. This is critical because Authentication and attestation are necessary to ensure safer computing in all environments. Trusted modules can be used in computing devices other than PCs, such as mobile phones or network equipment (Trusted Platform Module (TPM) Summary, 2008). . Figure 1: Components of a TPM 2.3.1 Hardware-based cryptography This cryptography makes certain that the data stored in hardware is guarded against malicious threats such as external software attacks. Also, many types of applications storing secrets on a TPM can be developed to strengthen security by increasing the difficulty of access without proper authorization. If the configuration of the platform has been altered as a result of unauthorized activities, access to data and secrets can be denied and sealed off using these applications. TPM is not responsible for control of other proprietary or vendor software running on a computer. However, TPM can store pre-run time configuration parameters, but it is other applications that determine and implement policies associated with this information. Also, processes can be made secure and applications such as email or secure document management. For example, if at boot time it is determined that a PC is not trustworthy because of unexpected changes in configuration, access to highly secure applications can be blocked until the issue is remedied. With a TPM, one can be more certain that artifacts necessary to sign secure email messages have not been affected by software attacks. And, with the use of remote attestation, other platforms in the trusted network can make a determination, to which extent they can trust information from another PC. Attestation or any other TPM functions do not transmit personal information of the user of the platform. 2.3.2 Capabilities TPM can improve security in many areas of computing, including e-commerce, citizen-to-government applications, online banking, confidential government communications and many other fields where greater security is required. Hardware-based security can improve protection for VPN, wireless networks, file encryption (as in Microsofts BitLocker) and password/PIN/credentials management. TPM specification is OS-agnostic, and software stacks exist for several Operating Systems. 2.4TPM Components Trusted Platform Module (TPM) is the core component of trusted computing. TPM is implemented as a secure hardware chip and provides the hardware Root of Trust. TPM has been designed to provide trusted computing based on Trusted Computing Group (TCG) specifications. TPM functions can be implemented either in hardware or software. A secure cryptographic chip (Figure 2) can be integrated on the motherboard of a computing device according to TPM 1.2 specifications (Angela, Renu Mary, Vinodh Ewards, 2013). Figure 2: A TPM 1.2 Chip (Source http://www.infineon.com) A logical layout of the TPM is represented below (Figure 3) along with the TPM components. Figure 3: TPM Component Diagram (Zimmer, Dasari, Brogam, 2009) Information flow is managed by the I/O component through the communication bus. The I/O component handles routing of messages to various components within the TPM and establishes access control for TPM functions and the Opt-in component. The non-volatile memory in the TPM is a repository for storing the Endorsement Key (EK) and the Storage Root Key (SRK). These long-term keys are the basis of key hierarchy. Owners authorization data such as password and persistent flags are also stored in the non-volatile memory (Trusted Computing Group, 2007). Platform Configuration Registers (PCR) are reset during power-offs and system restarts and can be stored in volatile or non-volatile region. In TPM v 1.1, minimum number of registers that can be implemented is 16. Registers 0-7 are allocated for TPM usage leaving the remaining registers (8-15) to be used by operating system and applications (Angela, Renu Mary, Vinodh Ewards, 2013). In TPM v 1.2, number of registers can be 24 or more and categorized as static PCRs (0-16) and dynamic PCRs (17-22). The Program Code, also known as Core Root of Trust for Measurement (CRTM) is the authoritative source for integrity measurements. Execution engine is responsible for initializing TPM and taking measurements. The execution engine is the driver behind the program code. RNG (Random Number Generator) is used for generating keys, nonce creation and to fortify passphrase entropy. The SHA-1 engine plays a key role in creating key Blobs and hashing large blocks of data. TPM modules can be shipped with various states ranging from disabled, and deactivated to fully enabled. The Opt-in component ensures the state of TPM modules during shipping. The RSA engine can be used for a variety purposes including key signing, encryption/decryption using storage keys and decryption using EK. The AIK (Attestation Identity Key) is an asymmetric key pair typically linked to the platform module that can be used to vouch for the validity of the platforms identity and configuration. The RSA key generation engine are used for creating symmetric keys of up to 2048 bits. 2.5 TPM Keys TCG keys can be categorized as signing or storage keys. Other key types defined by TCG are Platform, Identity, Binding, General and Legacy keys (Trusted Computing Group, 2007). Signing keys can be classified as general purpose keys and are asymmetric in nature. Application data and messages can be signed by the TPM using signing keys. Signing keys can be moved between TPM devices based on restrictions in place. Storage keys are asymmetric keys and primarily used for encrypting data and other keys as well as for wrapping keys. Attestation Identity Keys (AIK) are used for signing data pertaining to the TPM such as PCR register values. AIK are signing keys that cannot be exported. Endorsement Key (EK) is used for decrypting the owner authorization credentials as well as cryptic messages created by AIK. EK is not used for encryption or signing and cannot be exported. Bind keys (symmetric keys) come in handy to encrypt data on one platform and decrypt it on a different platform. Legacy keys can be imported from outside the TPM and used for signing and encrypting data. Authentication keys are responsible for securing the transport sessions related to TPM and are symmetric in nature. Endorsement Key (EK) in the TPM plays a critical role to maintain system security. TPM uses a private key EK to generate other keys which are bound to a specific EK. EK should be secured and protected from being compromised. A 160-bit AIK authentication value is necessary to use the AIK by TPM (Sparks, 2007). The parent key used for generating other keys should be loaded first and authenticated by users before TPM can load all other keys. The EK is unique to the TPM and embedded within the tamper resistant non-volatile memory (Angela, Renu Mary, Vinodh Ewards, 2013). Public EK is used for creating AIK certificates and during the process of encrypting data within the TPM. The private key pair of EK is not touched when generating signatures. Multiple AIKs can be stored within a TPM to ensure anonymity between various service providers requiring proof of identity. AIK keys should be stored in secure external storage (outside the TPM) to make them persistent. AIKs can be loaded on to th e volatile memory in the TPM when in use. TPM has a Storage Root Key which stays persistent. Keys are not stored permanently in TPM due to limited storage space. A brief description of the process involved in key generation, encryption, and decryption in TPM is outlined below (Osborn Challener, 2013). A new RSA key is generated by the TPM when a key creation request is initiated by a software. TPM concatenates a value to the RSA key, appends authorization data and then the data is encrypted using the public section of the Storage Root Key and sends an encrypted blob to the requested software. A request is sent for the key to be retrieved from the blob storage when requested by the software program. TPM uses the Storage Root Key for decryption and validates the proof value and password before loading the key into TPM memory. This loaded key is referred to as the parent key and can be used for subsequent key creation forming key hierarchies. The TMP security section discusses in some detail the various ways in which security is implemented and vulnerable. TPM authorization protocols in both version 1.2 and version 2.0 are addressed. Several examples of different types of TPM vulnerabilities are outlined as well as ways to verify the integrity of the system to protect against this vulnerabilities and what the future holds for TPM. 3.1 TPM Authorization Protocols TPM 1.2 Authorization The basic definition of TPM authorization is the process of verifying that software is allowed to use a TPM key. For TPM 1.2 this process is accomplished by utilizing a couple basic commands in an authorization session; typically using passwords or values stored in the Platform Configuration Registers (PCRs) which are referred to as authorization data. The three types of authorization sessions for TPM 1.2 are: Object Independent Authorization Protocol (OIAP), which creates a session that allows access to multiple objects, but works only for certain commands; Object Specific Authorization Protocol (OSAP), which creates a session that can manipulate only a single object, but allows for new authorization transfer; and Delegate-Specific Authorization Protocol (DSAP), which delegates access to an object without disclosing the authorization data (Nyman, Ekberg, Asokan, 2014). Commands are then used to manipulate the keys within an authorization session. Software can prove that it is trusted by sending a command which includes the password hash to verify it has knowledge of the password. Also the locking of non-volatile random-access memory (NVRAM) to PCRs and particular localities is utilized for two different authorizations; one for reading and one for writing. While effective, these authorization mechanisms created a relatively rigid authorization system which make it difficult to administrate the sharing of TPM keys and data (Osborn Chaneller, 2013). 3.1.2 TPM 2.0 Authorization The implementation of TPM 2.0 on the other hand, takes a couple different approaches by introducing enhanced authorization (EA). EA takes methods from the TPM 1.2 authorization methods and improves upon them by incorporating features mentioned in Table 1 below. Table 1. TPM 2.0 Authorization Feature Description Passwords in the clear Reduces overhead in environments where the security of hash message authentication (HMAC) may not be feasible due to its extra cost and complexity HMAC key In some cases when the software talking to the TPM is trusted but the OS is untrusted (like in a remote system), it could be useful to use HMAC for authorization the same way as used in TPM 1.2 Signature methods Allows IT employees to perform maintenance on a TPM by authenticating using a smart card or additional data such as a biometric fingerprint or GPS location. This ensures that passwords cant be shared or compromised by unauthorized users and that an additional verification check is conducted PCR values as a proxy for system boot state If the system management module software has been compromised, this prevents the release of the full-disk encryption key Locality as a proxy for command origins Can be used to indicate whether a command originated from the CPU in response to a special request. Time Can limit the use of a key to certain times of the day Internal counter values Limits the use of an object so that a key can only be used a certain number of times indicated by an internal counter Value in a non-volatile (NV) index Use of a key is restricted to when certain bits are set to 1 or 0 NV index Authorization is based on whether the NV index has been written Physical presence Requires proof that the user is physically in possession of the platform (Table created with information from (Arthur, Challener, Goldman, 2015)) These features can be combined to create more complex policies by using the logical operators AND or OR which allows for the creation of policies to include multifactor/multiuser authentication of resources, limited time constraints for resources, and/or revocation of resources. (Arthur, Challener, Goldman, 2015). 3.2TPM Vulnerabilities When ranked against other standards, TPM comes in as highly secure but that isnt to say that it is immune to all attacks. There are several vulnerabilities that can allow an attacker to circumvent TPMs level of security. The sections below explain a few vulnerabilities that attackers can use to exploit TPM, and the mitigation techniques one could deploy to manage the risk. Dictionary Attack TPM authorization relies on a 20-byte authorization code that is sent by the requestor which if not properly locked down can result in an attacker guessing their way past the authorization. TPM issues guidance on how best to mitigate and prevent these attacks; however, the guidance is not very detailed and rather leaves the specifics up to the implementer. For example, one could implement a design that has TPM disable further input whenever it encounters more than 3 failed attempts. This would effectively prevent online dictionary attacks and has the added benefit of also preventing Denial-of-Service attacks. Weve spoken about preventing online dictionary attacks but where the threat truly comes into play is with an offline-based attack. This vulnerability comes into play when the authorization code is easily guessable, or in other words, poorly implemented. An attacker could observe a given command, the associated Key-Hash Message Authentication Code (HMAC) sent by the requestor and finally, the TPM response back. Since the HMAC is created from the authorization code, session handle and nonces; an attacker can utilize a dictionary attack to try different nonces and authorization codes with the given HMAC algorithm. A match would then provide the attacker with the correct authorization code. This offline attack bypasses TPMs lockout policy and though the attacker but sift through the random nonces and authorization codes, the method is a viable means of attack because it can be reasonably executed given the availability of time and computing resources. The mitigation for this comes down t o proper configuration and ensuring that the authorization code is not easily guessable. DRAM Attack Though this attack is not directly against TPM, it is worth mentioning as it is a viable way to circumvent TPMs security authorization protocols. TPM maintains its keys within non-volatile memory within the TPM component; however, when these keys are pulled by a requestor or requesting application, they are stored within Dynamic Random Access Memory (DRAM). It is well known that one can easily exploit DRAM to extract valuable information (keys, passcodes, etc) with this even being demonstrated against Microsofts BitLocker encryption utility. During reboot, Windows would load the encryption keys stored within TPM into DRAM, prior to even prompting the user. Given this, an attacker could go in and dump the raw memory to an external device, obtain the keys, then utilize those keys to decrypt the disk. This flaw enabled attackers to gain access to data on stolen laptops, even with full disk encryption. This hits on how a system is designed and ensuring that every detail is accounted for. Even if your system has a TPM, it is only going to be as secure as the weakest component within the overall system. OIAP Replay Attack Replay attacks are a method used by many attackers across a multitude of systems. TPM is no exception and is vulnerable to replay attacks based on several characteristics. First, a TPM Object-Independent Authorization Protocol (OIAP) session can be left open for an indefinite period. The authorized session is only closed by the requestor whenever an abnormal message is received and finally, the HMAC that wraps the message can detect alterations to the message but cannot distinguish between a deliberate alteration and a simple network error. For example, an attacker would first capture a requestors authorized command for later use. The attacker then sends an abnormal message to the requestor which then fools it into resetting the session. The requestor is unable to distinguish between the abnormal message and a network error so no concern is raised. Since there is no concern, the TPM keeps the authorized session open, allowing the attacker the ability to replay the previously captured command through the open session. This could lead to the attacker being able to corrupt or even overwrite a subsequent command issued by the requestor. The TPM would not be able to notice this type of attack which is truly concerning based upon the foundational principles of TPM and its assurance of being able to detect unauthorized modifications to data. 3.3TPM Attestations Attestation is the method a platform uses to prove to another platform that it is in a particular configuration by using a digitally signed set of cryptographic hash values which creates a trust between platforms (Fisher, McCune, Andrews, 2011). The network server first creates a cryptographic random value (used to prevent replay attacks) called a nonce, which is then sent to the client. Software on the client then sends the nonce to the TPM and specifies an identity key. The TPM hashes the PCR values along with the nonce and then signs the hash with a private key. The client software sends this back to the server which then verifies the platform configuration by comparing the public portion of the identity key. This process provides hardware-based assurance that software on these platforms has not been modified. (Osborn Chaneller, 2013). Figure 5 provides a visual representation of attestation as provided by (Osborn Chaneller, 2013) Figure 5: Attestation In order for the attestation process to be valid however, it must be able to be proven that the TPM values from the client are not being spoofed. This can be accomplished using a couple of key components: attestation identity keys (AIK), which are created by the TPM and securely stored on disk before being reloaded into volatile TPM memory; endorsement keys (EK), which are hardcoded by the manufacturer into the TPM chip; and a privacy certificate authority (CA), which is a third-party validation entity. The first step of this process occurs when the public half of the AIK and EK is sent to the CA. The CA then uses the public EK certificate to verify that the request comes from a valid TPM by comparing it to a list of all valid TPM manufacturers public keys. The CA then puts the public AIK in a certificate and encrypts it with the public EK. This ensures that the only party that can decrypt it is the computer with the AIK of the corresponding TPM, thus confirming that the TPM from the requesting platform is trusted, and therefore, the attestation method is trusted as well. (Uppal Brandon, 2011). 3.4Application of TPM With the ever-evolving landscape of technology, there is an increased need for faster, more reliable and more secure methods of protecting private and personal data. TPM is a product of those evolving requirements and has thus been incorporated into many different sets of applications. This section will expand upon those sets of applications and delve into how TPM is utilized within the industry today. Encryption One of the most popular uses of TPM is to ensure the confidentiality of user data by providing full encryption capabilities for disks and file systems. The full disk encryption utilizes symmetric encryption with a key created from the users supplied passcode and used during the initial configuration and system boot. This protects against the loss of the disk drive and serves to facilitate disposal or repurposing of the drive since deleting the keys will result in the drive being wiped. The same method is utilized for the encryption of file systems and can be done so to protect specific nodes. Policy Enforcement With Bring-Your-Own-Device (BYOD) policies becoming more and more prevalent within the commercial businesses, TPM has found a use as a policy enforcement mechanism for remote access. TPM can be used to establish trust and verify a devices integrity before allowing remote connection to an organizations intranet. This utilization of TPM is comprised of a series of hashes that measure the predefined sequence of code loads, starting with the boot of the BIOS through the loading of the applications. The chain of hash measures are then compared to the stored value in order to validate the systems integrity. This is very useful for establishing the base operating environment and developing a baseline with which access control policies can be developed. Password Protection TPM protected storage provides a method of storing encryption/decryption keys as well as providing utility management of user passwords. Typically, the password manager retrieves the then encrypted password from TPM, decrypts it, and then sends it to the client application for validation. Since the passwords are usually sent to the client applications over plain-text, this is a serious vulnerability in which TPM can provide a solution for. Using the 20-byte authorization code, a TPM object is created for each user password with this then being saved in the objects authorization field. To verify a password, an application would need to send an OIAP request to access the TPM object. TPMs response to this request would indicated whether the password was correct or not. As a plus, this serves as both password storage and verification with the password never being sent to the application thus eliminating the vulnerability associated with plain-text. 3.5TPM Future TPM is compatible with many hardware and software platforms in use in todays commercial markets and is already in use by several major business functions, to include: Banking, E-Commerce, Biometrics and even Antivirus applications. Looking forward, TPM will play an even bigger role in the evolving mobile market, providing more enhanced security for cell phones, GPS tracking systems, tablets and more. TPM can be used to secure the Mobile Operating System (OS) from being modified by attackers and can be used to further secure authorized access by implementing a hard-coded digital signature solution. For GPS devices, TPM can be used to protect against the modification of system defined location parameters, thus preventing an attacker from adjusting those parameters to satisfy their ends. The biggest constraint facing TPMs implementation within the mobile realm is the space and power constraints on mobile devices. Research is being done on whether a mobile instantiation of TPM should be based on firmware, software or even hardware. A hardware implementation would be the most secure; however, the firmware-based option will likely prove to be the best approach as it will balance the security of the device with the size limitations. TPM is also being looked at with regards to providing security enhancements for cloud-based services. Cloud computing has migrated most of the standard desktop to a virtual and remotely

Friday, January 17, 2020

Ideal Student

With scholarship, one may subdue savants in court; Brave in spirit, one may fight courageous battles; Born a king, one might rule over an Empire; One may even land on the moon; But of what use are all these achievements, If one is not able to control the mind and the senses, And uphold eternal human values? My Teachers, Fellow Students, Boys and Girls! The world badly needs today ideal students with exemplary character instead of wealth and prosperity. The progress of the nation depends on such students alone. It is such sacred practices alone that have protected ideal students through the ages.My Teachers, Fellow Students, Boys and Girls! Unfortunately, Islamic values declined in the course of time among us. Today’s student has completely forgotten all about our Islamic culture and human values. We need to find them in our self and must spread in our society. We always speak truth and follow the path of honesty and justice. This is the most important factor to become an ideal student. Fellow Students, Boys and Girls! True Knowledge is another barometer against which we can measure in an Ideal Student.Knowledgeable students always respect by the society and admire by the world. His knowledge always makes pride to his parents, family and school. Fellow Students, Boys and Girls! We are the future citizens of this country. We all could become ideal students for the glory of our nation. It can be revived only if we become the torchbearers because falsehood, injustice, bad conduct, and evil are widespread in our country. We need to fight against them getting excellent knowledge and taking an active role to spread joy and happiness among our society. Thank You and God bless you all†¦!