首页> 外文会议>International conference on cryptology and network security >Resource Access Control in the Facebook Model
【24h】

Resource Access Control in the Facebook Model

机译:Facebook模型中的资源访问控制

获取原文
获取外文期刊封面目录资料

摘要

We study the fundamental security properties of resource access control as suggested by the operation of current social networks including Facebook. The "facebook model", which treats the server as a trusted party, suggests two fundamental properties, "owner privacy" and "server consistency", and two different modes of revocation, implicit and explicit. Through black-box experimentation, we determine Facebook's implementation for resource access control and we analyze its security properties within our formal model. We demonstrate, by the construction of explicit attacks, that the current implementation is not secure: specifically, we attack privacy with implicit revocation and server consistency. We evaluate the implications of the attacks and we propose amendments that can align the current implementation with all its intended security properties. To the best of our knowledge this is the first time that a security analysis of the Facebook resource access control mechanism is performed within a proper security model.
机译:我们研究了当前的社交网络(包括Facebook)的运行所建议的资源访问控制的基本安全性。将服务器视为受信任方的“ facebook模型”建议了两个基本属性,即“所有者隐私”和“服务器一致性”,以及两种不同的吊销模式,即隐式和显式。通过黑盒实验,我们确定了Facebook在资源访问控制方面的实现方式,并在我们的正式模型中分析了其安全性。通过构造显式攻击,我们证明了当前的实现是不安全的:具体地说,我们通过隐式吊销和服务器一致性来攻击隐私。我们评估了攻击的影响,并提出了可以使当前实现与其所有预期的安全属性保持一致的修正案。据我们所知,这是首次在适当的安全模型内对Facebook资源访问控制机制进行安全分析。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号