在基于属性的授权中保证匿名性

IF 3.8 2区 计算机科学 Q2 COMPUTER SCIENCE, INFORMATION SYSTEMS Journal of Information Security and Applications Pub Date : 2024-11-04 DOI:10.1016/j.jisa.2024.103895
Erin Lanus , Charles J. Colbourn , Gail-Joon Ahn
{"title":"在基于属性的授权中保证匿名性","authors":"Erin Lanus ,&nbsp;Charles J. Colbourn ,&nbsp;Gail-Joon Ahn","doi":"10.1016/j.jisa.2024.103895","DOIUrl":null,"url":null,"abstract":"<div><div>Attribute-based methods such as attribute-based access control make decisions based on attributes possessed by a subject rather than the subject’s identity. This allows for anonymous authorization but does not guarantee anonymity. If a policy can be composed that few subjects possess attributes to satisfy and is used for access control, the system can guess with high probability the requesting subject’s identity. Other approaches to achieving anonymity in attribute-based authorization do not address this attribute distribution problem. Suppose polices contain conjunctions of at most <span><math><mi>t</mi></math></span> attributes and the system must not be able to guess with probability greater than <span><math><mfrac><mrow><mn>1</mn></mrow><mrow><mi>r</mi></mrow></mfrac></math></span> the identity of a subject using a policy for authorization. The anonymity guarantee is <span><math><mi>r</mi></math></span> for maximum credential size <span><math><mi>t</mi></math></span>. An anonymizing array is a combinatorial array proposed as an abstraction to address the distribution problem by ensuring that any assignment of values to <span><math><mi>t</mi></math></span> attributes appearing in the array appears at least <span><math><mi>r</mi></math></span> times. Anonymizing arrays are related to covering arrays with higher coverage, but have an additional property, homogeneity, due to their application domain. We discuss the application of anonymizing arrays to guarantee anonymous authorization in attribute-based methods. Additionally, we develop metrics to compare arrays with the same parameters.</div></div>","PeriodicalId":48638,"journal":{"name":"Journal of Information Security and Applications","volume":"87 ","pages":"Article 103895"},"PeriodicalIF":3.8000,"publicationDate":"2024-11-04","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Guaranteeing anonymity in attribute-based authorization\",\"authors\":\"Erin Lanus ,&nbsp;Charles J. Colbourn ,&nbsp;Gail-Joon Ahn\",\"doi\":\"10.1016/j.jisa.2024.103895\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"<div><div>Attribute-based methods such as attribute-based access control make decisions based on attributes possessed by a subject rather than the subject’s identity. This allows for anonymous authorization but does not guarantee anonymity. If a policy can be composed that few subjects possess attributes to satisfy and is used for access control, the system can guess with high probability the requesting subject’s identity. Other approaches to achieving anonymity in attribute-based authorization do not address this attribute distribution problem. Suppose polices contain conjunctions of at most <span><math><mi>t</mi></math></span> attributes and the system must not be able to guess with probability greater than <span><math><mfrac><mrow><mn>1</mn></mrow><mrow><mi>r</mi></mrow></mfrac></math></span> the identity of a subject using a policy for authorization. The anonymity guarantee is <span><math><mi>r</mi></math></span> for maximum credential size <span><math><mi>t</mi></math></span>. An anonymizing array is a combinatorial array proposed as an abstraction to address the distribution problem by ensuring that any assignment of values to <span><math><mi>t</mi></math></span> attributes appearing in the array appears at least <span><math><mi>r</mi></math></span> times. Anonymizing arrays are related to covering arrays with higher coverage, but have an additional property, homogeneity, due to their application domain. We discuss the application of anonymizing arrays to guarantee anonymous authorization in attribute-based methods. Additionally, we develop metrics to compare arrays with the same parameters.</div></div>\",\"PeriodicalId\":48638,\"journal\":{\"name\":\"Journal of Information Security and Applications\",\"volume\":\"87 \",\"pages\":\"Article 103895\"},\"PeriodicalIF\":3.8000,\"publicationDate\":\"2024-11-04\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Journal of Information Security and Applications\",\"FirstCategoryId\":\"94\",\"ListUrlMain\":\"https://www.sciencedirect.com/science/article/pii/S2214212624001972\",\"RegionNum\":2,\"RegionCategory\":\"计算机科学\",\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q2\",\"JCRName\":\"COMPUTER SCIENCE, INFORMATION SYSTEMS\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Journal of Information Security and Applications","FirstCategoryId":"94","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S2214212624001972","RegionNum":2,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q2","JCRName":"COMPUTER SCIENCE, INFORMATION SYSTEMS","Score":null,"Total":0}
引用次数: 0

摘要

基于属性的方法,如基于属性的访问控制,是根据主体所拥有的属性而不是主体的身份做出决定。这种方法允许匿名授权,但不能保证匿名性。如果能制定出一种政策,很少有主体拥有能满足要求的属性,并将其用于访问控制,那么系统就很有可能猜出请求主体的身份。在基于属性的授权中实现匿名性的其他方法并不能解决这个属性分布问题。假设策略最多包含 t 个属性的连接,系统不能以大于 1r 的概率猜出使用策略进行授权的主体的身份。匿名数组是一种组合数组,作为解决分布问题的抽象概念,它确保数组中出现的 t 个属性的任何赋值至少出现 r 次。匿名数组与覆盖数组相关,具有更高的覆盖率,但由于其应用领域的原因,还具有一个额外的属性,即同质性。我们讨论了匿名阵列在基于属性的方法中保证匿名授权的应用。此外,我们还开发了用于比较具有相同参数的数组的指标。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
Guaranteeing anonymity in attribute-based authorization
Attribute-based methods such as attribute-based access control make decisions based on attributes possessed by a subject rather than the subject’s identity. This allows for anonymous authorization but does not guarantee anonymity. If a policy can be composed that few subjects possess attributes to satisfy and is used for access control, the system can guess with high probability the requesting subject’s identity. Other approaches to achieving anonymity in attribute-based authorization do not address this attribute distribution problem. Suppose polices contain conjunctions of at most t attributes and the system must not be able to guess with probability greater than 1r the identity of a subject using a policy for authorization. The anonymity guarantee is r for maximum credential size t. An anonymizing array is a combinatorial array proposed as an abstraction to address the distribution problem by ensuring that any assignment of values to t attributes appearing in the array appears at least r times. Anonymizing arrays are related to covering arrays with higher coverage, but have an additional property, homogeneity, due to their application domain. We discuss the application of anonymizing arrays to guarantee anonymous authorization in attribute-based methods. Additionally, we develop metrics to compare arrays with the same parameters.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
Journal of Information Security and Applications
Journal of Information Security and Applications Computer Science-Computer Networks and Communications
CiteScore
10.90
自引率
5.40%
发文量
206
审稿时长
56 days
期刊介绍: Journal of Information Security and Applications (JISA) focuses on the original research and practice-driven applications with relevance to information security and applications. JISA provides a common linkage between a vibrant scientific and research community and industry professionals by offering a clear view on modern problems and challenges in information security, as well as identifying promising scientific and "best-practice" solutions. JISA issues offer a balance between original research work and innovative industrial approaches by internationally renowned information security experts and researchers.
期刊最新文献
Fed-LSAE: Thwarting poisoning attacks against federated cyber threat detection system via Autoencoder-based latent space inspection Lightweight privacy-preserving authenticated key agreements using physically unclonable functions for internet of drones BCRS-DS: A Privacy-protected data sharing scheme for IoT based on blockchain and certificateless ring signature Privacy-preserving verifiable fuzzy phrase search over cloud-based data Robust coverless video steganography based on pose estimation and object tracking
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1