Li Duan, Yang Zhang, Shiping Chen, Xuan Liu, B. Cheng, Junliang Chen
{"title":"Model-Based Minimum Privacy Disclosure Recommendation for Authorization Policies","authors":"Li Duan, Yang Zhang, Shiping Chen, Xuan Liu, B. Cheng, Junliang Chen","doi":"10.1109/SCC.2016.59","DOIUrl":null,"url":null,"abstract":"This paper presents a privacy disclosure recommendation approach based on a privacy cost model. The approach involves selecting appropriate credentials or attributes from users, and automatically building a new credential to fulfill service's authorization policies. The recommendation principles consider three aspects: (1) the selected user's attributes in the new credential satisfy the requested service's authorization policy, (2) hiding user's credentials and attributes to keep private during the request procedure, and (3) the total privacy cost of users is minimum. In addition, an automated tool is designed and implemented to derive a new credential. The correctness of our approach is demonstrated and validated by a practical case. Experimental results and complexity analysis show that our approach is efficient.","PeriodicalId":115693,"journal":{"name":"2016 IEEE International Conference on Services Computing (SCC)","volume":"36 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2016-06-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2016 IEEE International Conference on Services Computing (SCC)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SCC.2016.59","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2
Abstract
This paper presents a privacy disclosure recommendation approach based on a privacy cost model. The approach involves selecting appropriate credentials or attributes from users, and automatically building a new credential to fulfill service's authorization policies. The recommendation principles consider three aspects: (1) the selected user's attributes in the new credential satisfy the requested service's authorization policy, (2) hiding user's credentials and attributes to keep private during the request procedure, and (3) the total privacy cost of users is minimum. In addition, an automated tool is designed and implemented to derive a new credential. The correctness of our approach is demonstrated and validated by a practical case. Experimental results and complexity analysis show that our approach is efficient.