A Card Requirements Language Enabling Privacy-Preserving Access Control

被引:7
作者
Camenisch, Jan [1 ]
Moedersheim, Sebastian [1 ]
Neven, Gregory [1 ]
Preiss, Franz-Stefan [1 ]
Sommer, Dieter [1 ]
机构
[1] IBM Res Zurich, Zurich, Switzerland
来源
SACMAT 2010: PROCEEDINGS OF THE 15TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES | 2010年
关键词
Access Control; Policy Languages; Privacy; Anonymous Credentials; Digital Credentials;
D O I
10.1145/1809842.1809863
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
We address the problem of privacy-preserving access control in distributed systems. Users commonly reveal more personal data than strictly necessary to be granted access to online resources, even though existing technologies, such as anonymous credential systems, offer functionalities that would allow for privacy-friendly authorization. An important reason for this lack of technology adoption is, as we believe, the absence of a suitable authorization language offering adequate expressiveness to address the privacy-friendly functionalities. To overcome this problem, we propose an authorization language that allows for expressing access control requirements in a privacy-preserving way. Our language is independent from concrete technology, thus it allows for specifying requirements regardless of implementation details while it is also applicable for technologies designed without privacy considerations. We see our proposal as an important step towards making access control systems privacy-preserving.
引用
收藏
页码:119 / 128
页数:10
相关论文
共 39 条
  • [1] [Anonymous], U PROV SDK OV CRED W
  • [2] [Anonymous], 2008, 5280 IETF RFC
  • [3] [Anonymous], 2005, ASS PROT OASIS SEC A
  • [4] [Anonymous], 2007, OpenID Authentication 2.0 - Final
  • [5] [Anonymous], PLATF PRIV PREF P3P
  • [6] [Anonymous], 1999, Ph.D. thesis
  • [7] [Anonymous], SECURE INTERNET PROG
  • [8] Appel A. W., ACM CCS 1999
  • [9] A privacy-aware access control system
    Ardagna, C.
    Cremonini, M.
    di Vimercati, S.
    Samarati, P.
    [J]. JOURNAL OF COMPUTER SECURITY, 2008, 16 (04) : 369 - 397
  • [10] Exploiting cryptography for privacy-enhanced access control: A result of the PRIME Project
    Ardagna, Claudio A.
    Camenisch, Jan
    Kohlweiss, Markulf
    Leenes, Ronald
    Neven, Gregory
    Priem, Bart
    Samarati, Pierangela
    Sommer, Dieter
    Verdicchio, Mario
    [J]. JOURNAL OF COMPUTER SECURITY, 2010, 18 (01) : 123 - 160