首页> 外文会议>International Conference on Information and Communications Security >Beyond User-to-User Access Control for Online Social Networks
【24h】

Beyond User-to-User Access Control for Online Social Networks

机译:除了在线社交网络的用户到用户访问控制之外

获取原文

摘要

With the development of Web 2.0 technologies, online social networks are able to provide open platforms to enable the seamless sharing of profile data to enable public developers to interface and extend the social network services as applications (or APIs). At the same time, these open interfaces pose serious privacy concerns as third party applications are usually given full read access to the user profiles. Current related research has focused on mainly user-to-user interactions in social networks, and seems to ignore the third party applications. In this paper, we present an access control framework to manage the third party to user interactions. Our framework is based on enabling the user to specify the data attributes to be shared with the application and at the same time be able to specify the degree of specificity of the shared attributes. We model applications as finite state machines, and use the required user profile attributes as conditions governing the application execution. We formulate the minimal attribute generalization problem and we propose a solution that maps the problem to the shortest path problem to find the minimum set of attribute generalization required to access the application services.
机译:随着Web 2.0技术的开发,在线社交网络能够提供开放平台,以实现简档数据的无缝共享,使公共开发人员能够接口并将社交网络服务扩展为应用程序(或API)。与此同时,这些开放接口构成严重隐私问题,因为第三方应用程序通常会为用户配置文件提供完全读取的访问权限。当前相关研究主要集中在社交网络中的用户对用户的互动,似乎忽略了第三方应用程序。在本文中,我们介绍了一个访问控制框架来管理到用户交互的第三方。我们的框架是基于使用户能够指定要与应用程序共享的数据属性,同时能够指定共享属性的特定程度。我们将应用程序应用为有限状态机,并使用所需的用户配置文件属性作为管理应用程序执行的条件。我们制定了最小的属性泛化问题,我们提出了一个解决方案,将问题映射到最短路径问题,以查找访问应用程序服务所需的最小属性泛化集。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号