V. NETWORK DESIGN
In this section, different aspects of secure network design should be covered. The basics concepts of the cryptographic checksum to ensure message integrity and secrecy should be described. The concept of a trusted network should be developed. Of course, it is complicated by two factors:
- the number of components/media/systems involved in a network, and
- the fact that active subjects interfere with other active subjects on a network.
The possibility of compromise of a node or a communications link is serious because it implies a continuing need for assurance of the authenticity of any trusted network base. A paper by Randell and Rushby represents an example of the separation of a distributed system into trusted and untrusted components.