【24h】

Cryptographically Enforced Four-Eyes Principle

机译:密码执行的四眼原理

获取原文

摘要

The 4-eyes principle (4EP) is a well-known access control and authorization principle, and used in many scenarios to minimize the likelihood of corruption. It states that at least two separate entities must approve a message before it is considered authentic. Hence, an adversarial party aiming to forge bogus content is forced to convince other parties to collude in the attack. We present a formal framework along with a suitable security model. Namely, a party sets a policy for a given message which involves multiple additional approvers in order to authenticate the message. Finally, we show how these signatures are black-box realized by secure sanitizable signature schemes.
机译:四眼原则(4EP)是一种众所周知的访问控制和授权原则,在许多情况下都使用它来最大程度地减少损坏的可能性。它指出,至少有两个单独的实体必须先批准一条消息,然后该消息才被视为真实消息。因此,旨在伪造虚假内容的对抗方被迫说服其他方在袭击中串通。我们提出了一个正式的框架以及合适的安全模型。即,一方为给定消息设置策略,该策略涉及多个附加批准者以认证消息。最后,我们展示如何通过安全的可清理签名方案来实现这些签名的黑匣子。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号