首页> 外文会议>5th ACM symposium on information, computer and communications security 2009 >Oblivious Enforcement of Hidden Information Release Policies
【24h】

Oblivious Enforcement of Hidden Information Release Policies

机译:隐性执行隐藏信息发布策略

获取原文
获取原文并翻译 | 示例

摘要

In a computing system, sensitive data must be protected by release policies that determine which principals are authorized to access that data. In some cases, such a release policy could refer to information about the requesting principal that is unavailable to the information provider. Furthermore, the release policy itself may contain sensitive information about the resource that it protects. In this paper we describe a scheme for enforcing information release policies whose satisfaction cannot be verified by the entity holding the protected information, but only by the entity requesting this information. Not only does our scheme prevent the information provider from learning whether the policy was satisfied, but it also hides the information release policy being enforced from the requesting principal. Unlike previous approaches, our construction requires no guesswork or wasted computation on the part of the information requester. The information release policies that we consider can contain third-party assertions that themselves have release conditions that must be satisfied; we show that our system functions correctly even when these dependencies form cycles.
机译:在计算系统中,敏感数据必须受发布策略保护,发布策略确定授权哪些主体访问该数据。在某些情况下,这种释放策略可以引用信息提供者不可用的有关请求主体的信息。此外,发布策略本身可能包含有关其所保护资源的敏感信息。在本文中,我们描述了一种实施信息发布策略的方案,该方案的满意程度不能由拥有受保护信息的实体来验证,而只能由请求此信息的实体来验证。我们的方案不仅阻止信息提供者了解策略是否得到满足,而且还向请求的主体隐藏了正在实施的信息发布策略。与以前的方法不同,我们的构造不需要信息请求者的猜测或浪费的计算。我们考虑的信息发布策略可以包含第三方声明,这些声明本身具有必须满足的发布条件;我们证明即使这些依赖关系形成循环,我们的系统也能正常运行。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号