首页> 外文期刊>Annals of Mathematics and Artificial Intelligence >Controlled query evaluation for known policies by combining lying and refusal
【24h】

Controlled query evaluation for known policies by combining lying and refusal

机译:通过结合说谎和拒绝对已知策略进行受控查询评估

获取原文
获取原文并翻译 | 示例

摘要

Controlled query evaluation enforces security policies for confidentiality in information systems. It deals with users who may apply background knowledge to infer additional information from the answers to their queries. For each query the correct answer is first judged by some censor and then - if necessary - appropriately modified to preserve security. In previous approaches, modification has been done uniformly, either by lying or by refusal. A drawback of lying is that all disjunctions of secrets must always be protected. On the other hand, refusal may hide an answer even when the correct answer does not immediately reveal a secret. In this paper we introduce a hybrid answer modification method that appropriately combines lying and refusal. We prove that the new method is secure under the models of known potential secrets and of known secrecies, respectively. Furthermore, we demonstrate that the combined approach can be more cooperative than uniform lying and uniform refusal, and enjoys the advantages of both.
机译:受控查询评估为信息系统的机密性实施了安全策略。它与可能应用背景知识以从查询答案中推断出其他信息的用户打交道。对于每个查询,首先由某个检查员判断正确答案,然后(必要时)进行适当修改以保持安全。在以前的方法中,修改是通过撒谎或拒绝来统一完成的。说谎的缺点是必须始终保护所有秘密分离。另一方面,即使正确答案不能立即揭示秘密,拒绝也会掩盖答案。在本文中,我们介绍了一种混合答案修改方法,该方法将撒谎和拒绝相结合。我们证明该新方法分别在已知潜在秘密和已知保密性的模型下是安全的。此外,我们证明了结合的方法比统一的撒谎和统一的拒绝更能合作,并享有两者的优势。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号