Computing systems, networks and requirements
| English | 中文 | Pinyin · 拼音 |
|---|---|---|
| authentication/ɔːˌθentɪˈkeɪʃn/ | 身份验证 | shēn fèn yàn zhèng |
| authorization/ˌɔːθəraɪˈzeɪʃn/ | 授权 | shòu quán |
What would explain this observation?
- A school booking system can calculate correctly and still fail if users lose access or records are disclosed. Success includes the system context.
- Start with a prediction. State the quantities or features you would compare, then decide what evidence could distinguish two explanations.
Build the model
- A computer system combines hardware, software, data and people. A network enables communication using protocols. Requirements should distinguish function from constraints such as availability, security and accessibility.
- authentication 身份验证: Checking an asserted identity; authorization 授权: Determining permitted actions.
Which question concerns authorization?
Separate authentication from authorization. Authentication checks identity; authorization determines permitted actions. A threat model connects a valuable asset, a possible attack and an appropriate control.
Match each technical term to its precise meaning.
Use the definitions to distinguish related quantities and processes.
Choose evidence that can test it
- Separate authentication from authorization. Authentication checks identity; authorization determines permitted actions. A threat model connects a valuable asset, a possible attack and an appropriate control.
- Use a fictitious school dataset to define users and permissions. Draw data flows, compare validation and verification, and specify tests for normal, boundary and invalid input. Do not use real credentials or student records in exercises.
Which two habits make the investigation or model in this case more defensible?
Use a fictitious school dataset to define users and permissions. Draw data flows, compare validation and verification, and specify tests for normal, boundary and invalid input. Do not use real credentials or student records in exercises.
Work from known quantities
- State the known values and their units. Choose the relation because its assumptions fit this case, then rearrange before substitution.
- Known: a file contains 12 megabytes, where this example defines one megabyte as one million bytes. Bits = bytes×8 = 12×1,000,000×8 = 96,000,000 bits. At 8,000,000 bits per second, ideal time = size/rate = 12 s, excluding overhead.
A 40 million bit file transfers at 5 million bits per second. Find ideal time. Use the same sequence: known quantities → model → relation → substitution → unit and interpretation.
A 40 million bit file transfers at 5 million bits per second. Find ideal time.
The result is 8 s. Known: a file contains 12 megabytes, where this example defines one megabyte as one million bytes. Bits = bytes×8 = 12×1,000,000×8 = 96,000,000 bits. At 8,000,000 bits per second, ideal time = size/rate = 12 s, excluding overhead.
Check the conclusion and its limits
- Bandwidth is not actual end-to-end throughput. Encryption does not by itself ensure correct authorization or remove every security risk.
- Return to the original observation. Explain what the result supports, which conditions it assumes, and one way to test a competing explanation.
Encryption guarantees that every user has appropriate access permissions. This claim is false: Bandwidth is not actual end-to-end throughput. Encryption does not by itself ensure correct authorization or remove every security risk.
Computing systems, networks and requirements: Separate authentication from authorization. Authentication checks identity; authorization determines permitted actions. A threat model connects a valuable asset, a possible attack and an appropriate control.
Encryption guarantees that every user has appropriate access permissions.
Bandwidth is not actual end-to-end throughput. Encryption does not by itself ensure correct authorization or remove every security risk.
Checking an asserted identity: write the technical term.
authentication means Checking an asserted identity.