Privacy Enhanced Automated Trust Negotiation

نویسندگان

  • Jiangtao Li
  • Mikhail Atallah
چکیده

Li, Jiangtao. Ph.D., Purdue University, May, 2006. Privacy Enhanced Automated Trust Negotiation. Major Professors: Mikhail J. Atallah and Ninghui Li. In automated trust negotiation, two parties exchange digitally signed credentials that contain attribute information to establish trust and make access control decisions. Because the information in question is often sensitive, credentials are protected according to access control policies. In traditional trust negotiation, credentials are transmitted either in their entirety or not at all. This approach can at times fail unnecessarily, either because a cyclic dependency makes neither negotiator willing to reveal her credential before her opponent, because the opponent must be authorized for all attributes packaged together in a credential to receive any of them, or because it is necessary to disclose the precise attribute values, rather than merely proving they satisfy some predicate (such as being over 21 years of age). In this thesis, we introduce a number of techniques that address the previous problems. In particular, • We propose Oblivious Attribute Certificates (OACerts), an attribute certificate scheme in which a certificate holder can select which attributes to use and how to use them. In particular, a user can use attribute values stored in an OACert to obtain a resource from a service provider without revealing any information about these values. Using OACerts, we develop a policy-hiding access control scheme that protects both sensitive attribute values and sensitive policies. • We present a privacy-preserving trust negotiation protocol that enforces each credential’s policy (thereby protecting sensitive credentials). Our result is not achieved through the routine use of standard techniques to implement, in this framework, one of the known strategies for trust negotiations (such as the “eager strategy”).

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

A Unified Scheme for Resource Protection in Automated Trust Negotiation

Automated trust negotiation is an approach to establishing trust between strangers through iterative disclosure of digital credentials. In automated trust negotiation, access control policies play a key role in protecting resources from unauthorized access. Unlike in traditional trust management systems, the access control policy for a resource is usually unknown to the party requesting access ...

متن کامل

A Message from the General Chairs

This paper covers topics related to privacy and trust negotiation applied in pervasive information systems. We consider the turbulent nature of pervasive environments and highlight special privacy and trust issues that arise from it. The current state of trust negotiation is summarized. We propose an extended negotiation model that not only enables parties’ access control but produces a privacy...

متن کامل

A Privacy Preserving Enhanced Trust Building Mechanism for Web Services

With the development of web services, more effective trust building mechanisms are needed to deploy diverse trust models in a web services environment. The lack of mechanisms that can dynamically build trust relationships while preserving privacy impedes progress. Current web service technologies encourage a client to reveal all its private attributes in a pre-packaged digital credential to the...

متن کامل

Distributed Authorization by Multiparty Trust Negotiation

Automated trust negotiation (ATN) is a promising approach to establishing trust between two entities without any prior knowledge of each other. However, real-world authorization processes often involve online input from third parties, which ATN does not support. In this paper, we introduce multiparty trust negotiation (MTN) as a new approach to distributed authorization. We define a Datalog-bas...

متن کامل

Multiparty Trust Negotiation: A New Approach to Distributed Authorization

Automated trust negotiation (ATN) is a promising approach to establishing trust between two entities without any prior knowledge of each other. However, real-world authorization processes often involve online input from third parties, which ATN does not support. In this paper, we introduce multiparty trust negotiation (MTN) as a new approach to distributed authorization. We define a Datalog-bas...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2006