首页> 外文会议>ACM workshop on Privacy in the Electronic Society >Protecting sensitive attributes in automated trust negotiation
【24h】

Protecting sensitive attributes in automated trust negotiation

机译:在自动信任协商中保护敏感属性

获取原文

摘要

Exchange of attribute credentials is a means to establish mutual trust between strangers that wish to share resources or conduct business transactions. Automated Trust Negotiation (ATN) is an approach to regulate the flow of sensitive attributes during such an exchange. Recently, it has been noted that early ATN designs do not adequately protect the privacy of negotiating parties. While unauthorized access to credentials can be denied, sensitive information about the attributes they carry may easily be inferred based on the behavior of negotiators faithfully adhering to proposed negotiation procedure. Some proposals for correcting this problem do so by sacrificing the ability to effectively use sensitive credentials. We study an alternative design that avoids this pitfall by allowing negotiators to define policy protecting the attribute itself, rather than the credentials that prove it. We show how such a policy can be enforced. We address technical issues with doing this in the context of trust management-style credentials, which carry delegations and enable one attribute to be inferred from others, and in the context where credentials are stored in a distributed way, and must be discovered and collected before being used in ATN.
机译:交换属性凭证是在希望共享资源或进行业务交易的陌生人之间建立相互信任的一种手段。自动信任协商(ATN)是一种在此类交换过程中调节敏感属性流的方法。最近,已经注意到,早期的ATN设计不能充分保护谈判方的隐私。虽然可以拒绝未经授权访问凭据,但可以根据忠实遵守提议的协商程序的谈判者的行为轻松推断出有关凭据所携带属性的敏感信息。纠正此问题的一些建议是通过牺牲有效使用敏感凭据的能力来实现的。我们研究了一种替代设计,它通过允许谈判者定义保护属性本身(而不是证明属性的凭证)来避免这种陷阱。我们展示了如何执行这样的策略。我们在信任管理样式的凭据的上下文中解决此问题,这些凭据带有委托并允许从另一个属性中推论出一个属性,并且在凭据以分布式方式存储的上下文中,必须在发现和收集之前在ATN中使用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号