首页> 外文OA文献 >Achieving Privacy in Trust Negotiations with an Ontology-Based Approach
【2h】

Achieving Privacy in Trust Negotiations with an Ontology-Based Approach

机译:使用基于本体的方法在信任协商中实现隐私

摘要

The increasing use of Internet in a variety of distributed multiparty interactions and transactions with strong real-time requirements has pushed the search for solutions to the problem of attribute-based digital interactions. A promising solution today is represented by automated trust negotiation systems. Trust negotiation systems allow subjects in different security domains to securely exchange protected resources and services. These trust negotiation systems, however, by their nature, may represent a threat to privacy in that credentials, exchanged during negotiations, often contain sensitive personal information that may need to be selectively released. In this paper, we address the problem of preserving privacy in trust negotiations. We introduce the notion of privacy preserving disclosure, that is, a set that does not include attributes or credentials, or combinations of these, that may compromise privacy. To obtain privacy preserving disclosure sets, we propose two techniques based on the notions of substitution and generalization. We argue that formulating the trust negotiation requirements in terms of disclosure policies is often restrictive. To solve this problem, we show how trust negotiation requirements can be expressed as property-based policies that list the properties needed to obtain a given resource. To better address this issue, we introduce the notion of reference ontology, and formalize the notion of trust requirement. Additionally, we develop an approach to derive disclosure policies from trust requirements and formally state some semantics relationships (i.e., equivalence, stronger than) that may hold between policies. These relationships can be used by a credential requestor to reason about which disclosure policies he/she should use in a trust negotiation.
机译:在具有强大实时性的各种分布式多方交互和交易中,Internet的使用越来越广泛,这促使人们寻求基于属性的数字交互问题的解决方案。如今,一种有前途的解决方案以自动信任协商系统为代表。信任协商系统允许不同安全域中的主体安全地交换受保护的资源和服务。但是,这些信任协商系统本质上可能会对隐私构成威胁,因为在协商期间交换的凭据通常包含敏感的个人信息,可能需要有选择地发布这些信息。在本文中,我们解决了在信任协商中保护隐私的问题。我们介绍了隐私保护公开的概念,即不包含可能损害隐私的属性或凭据或其组合的集合。为了获得保护隐私的公开集,我们基于替换和泛化的概念提出了两种技术。我们认为,根据披露政策来制定信任谈判要求通常是限制性的。为了解决此问题,我们展示了如何将信任协商要求表达为基于属性的策略,该策略列出了获取给定资源所需的属性。为了更好地解决这个问题,我们引入了参考本体的概念,并对信任需求的概念进行了形式化。此外,我们开发了一种从信任要求中得出公开政策的方法,并正式陈述了政策之间可能存在的一些语义关系(即等价关系,强于等价关系)。凭证请求者可以使用这些关系来推断他/她应在信任协商中使用哪些公开策略。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号