首页> 外文会议>6th ACM workshop on digital identity management 2010 >Privacy-Preserving Similarity Measurement for Access Control Policies
【24h】

Privacy-Preserving Similarity Measurement for Access Control Policies

机译:访问控制策略的隐私保护相似性度量

获取原文
获取原文并翻译 | 示例

摘要

The emergence of global-scale infrastructures for outsourcing data and content to service providers (e.g., cloud computing) creates unprecedented opportunities for data owners to expand their operations and increase their customer base. On the other hand, each data owner (DO) has a certain set of access control policies, which may be different than those of the service providers (SP). Therefore, to enable effective outsourcing, it is important for the DOs to choose SPs with similar access control policies. Several techniques that measure policy similarity have been proposed in previous work, but they assume that policies are publicly accessible. However, in a global-scale environment without well-established relationships of trust, participants may not be willing to reveal their policies to every other stakeholder. Therefore, the need arises to perform policy similarity in a privacy-preserving manner. Specifically, we propose a technique that allows similarity evaluation of encrypted policies. Our technique relies on an existing encryption method for numerical data called asymmetric scalar product-preserving encryption (ASPE). ASPE allows answering of nearest-neighbor queries without the need to reveal the plaintext contents of either the query or the data. We adapt ASPE to support access control policies, and we present a case study of how private policy similarity evaluation is performed within our proposed framework.
机译:用于将数据和内容外包给服务提供商(例如云计算)的全球规模基础架构的出现为数据所有者提供了前所未有的机会,以扩展其业务并增加其客户群。另一方面,每个数据所有者(DO)都有一组特定的访问控制策略,这些策略可能与服务提供商(SP)的访问控制策略不同。因此,为了实现有效的外包,对于DO来说,选择具有类似访问控制策略的SP至关重要。在先前的工作中已经提出了几种测量策略相似性的技术,但是它们假定策略是公开可用的。但是,在没有公认的信任关系的全球环境中,参与者可能不愿意向其他所有利益相关者披露其政策。因此,需要以隐私保护的方式执行策略相似性。具体来说,我们提出了一种允许对加密策略进行相似性评估的技术。我们的技术依赖于一种用于数字数据的现有加密方法,称为非对称标量积保存加密(ASPE)。 ASPE允许回答最邻近的查询,而无需透露查询或数据的明文内容。我们使ASPE适应支持访问控制策略,并提出了一个案例研究,说明如何在我们提出的框架内执行私有策略相似性评估。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号