A unified scheme for resource protection in automated trust negotiation

被引:61
作者
Yu, T [1 ]
Winslett, M [1 ]
机构
[1] Univ Illinois, Dept Comp Sci, Urbana, IL 61801 USA
来源
2003 IEEE SYMPOSIUM ON SECURITY AND PRIVACY, PROCEEDINGS | 2003年
关键词
D O I
10.1109/SECPRI.2003.1199331
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Automated trust negotiation is an approach to establishing trust between strangers through iterative disclosure of digital credentials. In automated trust negotiation, access control policies play a key role in protecting resources from unauthorized access. Unlike in traditional trust management systems, the access control policy for a resource is usually unknown to the party requesting access to the resource, when trust negotiation starts. The negotiating parties can rely on policy disclosures to learn each other's access control requirements. However a policy itself may also contain sensitive information. Disclosing policies' contents unconditionally may leak valuable business information or jeopardize individuals' privacy. In this paper we propose UniPro, a unified scheme to model protection of resources, including policies, in trust negotiation. UniPro improves on previous work by modeling policies as first-class resources, protecting them in the same way as other resources, providing fine-grained control over policy disclosure, and clearly distinguishing between policy disclosure and policy satisfaction, which gives users more flexibility in expressing their authorization requirements. We also show that UniPro can be used with practical negotiation strategies without jeopardizing autonomy in the choice of strategy, and present criteria under which negotiations using UniPro are guaranteed to succeed in establishing trust.
引用
收藏
页码:110 / 122
页数:13
相关论文
共 17 条
[1]  
BLAZE M, 1998, SEC PROT WORKSH CAMB
[2]  
BONATTI P, 2000, C COMP COMM SEC ATH
[3]  
BONATTI P, 2000, ACM C COMP COMM SEC
[4]  
Brands Stefan, 2000, Rethinking Public Key Infrastructures and Digital Certificates: Building in Privacy
[5]  
DAMIANOU D, 2001, 2 INT WORKSH POL DIS
[6]  
HERZBERG A, 2000, IEEE S SEC PRIV OAKL
[7]  
HESS A, 2002, NETW DISTR SYST SEC
[8]  
*INT TEL UN, 1997, X509 INT TEL UN
[9]  
JOHNSON W, 1998, IEEE INT WORKSH EN T
[10]  
LI N, 2001, C COMP COMM SEC PHIL