Towards privacy-preserving access control with hidden policies, hidden credentials and hidden decisions

Towards privacy-preserving access control with hidden policies, hidden credentials and hidden decisions
复制标题

DOI:
10.1109/pst.2012.6297915
复制
发表时间:
2012-07
期刊:
2012 Tenth Annual International Conference on Privacy, Security and Trust
影响因子:
--
通讯作者:
Marian Harbach;S. Fahl;Michael Brenner;T. Muders;Matthew Smith
Marian Harbach;S. Fahl;Michael Brenner;T. Muders;Matthew Smith
中科院分区:
其他
文献类型:
--
作者:
Marian Harbach;S. Fahl;Michael Brenner;T. Muders;Matthew Smith

文献摘要

被引文献

相似文献

云技术在医学等敏感应用领域的日益采用,给授权过程中维护相关方的隐私带来了新的问题。在这些领域中,诚实但好奇的服务提供商可以纯粹从授权过程中获取敏感信息。在本文中,我们详细讨论了这个日益严重的问题,包括一个具体的例子,并认为需要结合隐藏凭证、隐藏策略和隐藏决策。然后我们表明,先前工作中探索的机制仅涵盖该问题的个别方面,但如果不对要保护的资源、政策或主体做出限制性假设,则无法实现全面的解决方案。作为解决这个问题的第一步,我们引入了使用同态密码学的抽象基础,以提供所需的隐私组合作为其他访问控制(AC)机制的包装器。我们实现了隐藏策略、隐藏凭据甚至隐藏访问控制决策,以便 AC 请求的主体仅了解是否授予访问权限。同时,资源的提供者在策略决策点什么也学不到,而仅在策略执行点了解单个资源的访问频率。我们假设这是授权过程中可实现的最大保护级别,而不对要保护的资源、政策或主体做出限制性假设。一旦同态密码学获得令人满意的性能,我们的模型就可以用于透明地将这种保护添加到其他访问控制模型中。
The growing adoption of cloud technology in sensitive application domains, such as medicine, gives rise to new problems in maintaining the privacy of the involved parties during authorisation. In such domains, an honest but curious service provider can derive sensitive information purely from the authorisation process. In this paper, we present a detailed discussion of this rising problem including a concrete example and argue the need for the combination of hidden credentials, hidden policies and hidden decisions. We then show that mechanisms explored in previous work only cover individual aspects of this problem, but do not achieve a comprehensive solution without making restrictive assumptions on the resources, policies or subjects to be protected. As a first step towards solving this problem, we introduce an abstract foundation for using homomorphic cryptography to provide the required combination of privacy as a wrapper for other access control (AC) mechanisms. We achieve hidden policies, hidden credentials and even hidden access control decisions, so that the subject of an AC request only learns whether or not access was granted. Meanwhile, the provider of a resource learns nothing at the policy decision point and only access frequencies for individual resources at the policy enforcement point. We postulate that this is the maximum achievable level of protection in the authorisation process, without making restrictive assumptions on the resources, policies or subjects to be protected. Once homomorphic cryptography achieves satisfactory performance, our model can be used to transparently add this protection to other access control models.