|
ABSTRACT
In trust negotiation and other distributed proving systems, networked entities cooperate to form proofs that are justi?ed by collections of certi?ed attributes. These attributes may be obtained through interactions with any number of external entities and are collected and validated over an extended period of time. Though these collections of credentials in some ways resemble partial system snapshots,these systems currently lack the notion of a consistent global state in which the satisfaction of authorization policies should be checked. In this paper, we argue that unlike the notions of consistency studied in other areas of distributed computing, the level of consistency required during policy evaluation is predicated solely upon the security requirements of the policy evaluator. As such,there is little incentive for entities to participate in complicated consistency preservation schemes like those used in distributed computing,distributed databases, and distributed shared memory. We go on to show that the most intuitive notion of consistency fails to provide basic safety guarantees under certain circumstances and then propose several more refined notions of consistency which provide stronger safety guarantees. We provide algorithms that allow each of these re ?ned notions of consistency to be attained in practice with minimal overheads.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
| |
1
|
|
| |
2
|
|
| |
3
|
|
| |
4
|
|
| |
5
|
|
 |
6
|
|
| |
7
|
|
 |
8
|
|
 |
9
|
|
| |
10
|
R. Housely, W. Ford, W. Polk, and D. Solo. Internet X.509 Public Key Infrastructure Certificate and CRL Pro ?le. IETF RFC 2459, Jan. 1999.
|
 |
11
|
|
| |
12
|
H. Koshutanski and F. Massacci. Interactive credential negotiation for stateful business processes. In International Conference on Trust Management May 2005.
|
 |
13
|
|
| |
14
|
A. J. Lee and M. Winslett. Safety and consistency in policy-based authorization systems (extended version). Technical Report UIUCDCS-R-2006-2761,University of Illinois at Urbana-Champaign, Aug. 2006.
|
 |
15
|
|
| |
16
|
N. Li and J. Mitchell. RT: A role-based trust-management framework. In DARPA Information Survivability Conference and Exposition Apr. 2003.
|
| |
17
|
|
| |
18
|
D. L. Mills. Network Time Protocol (Version 3) Specification, Implementation and Analysis. IETF RFC 1305, Mar. 1992.
|
| |
19
|
K. Minami and D. Kotz. Scalability in a secure distributed proof system. In International Conference on Pervasive Computing May 2006.
|
| |
20
|
|
| |
21
|
|
| |
22
|
|
| |
23
|
W. H. Winsborough and N. Li. Safety in automated trust negotiation. In IEEE Symposium on Security and Privacy May 2004.
|
| |
24
|
Marianne Winslett , Ting Yu , Kent E. Seamons , Adam Hess , Jared Jacobson , Ryan Jarvis , Bryan Smith , Lina Yu, Negotiating Trust on the Web, IEEE Internet Computing, v.6 n.6, p.30-37, November 2002
[doi> 10.1109/MIC.2002.1067734]
|
 |
25
|
|
 |
26
|
|
 |
27
|
|
CITED BY 4
|
|
|
|
|
|
|
|
Anna C. Squicciarini , Alberto Trombetta , Elisa Bertino , Stefano Braghin, Identity-based long running negotiations, Proceedings of the 4th ACM workshop on Digital identity management, October 31-31, 2008, Alexandria, Virginia, USA
|
|
|
Ram Krishnan , Jianwei Niu , Ravi Sandhu , William H. Winsborough, Stale-safe security properties for group-based secure information sharing, Proceedings of the 6th ACM workshop on Formal methods in security engineering, p.53-62, October 27-27, 2008, Alexandria, Virginia, USA
|
|