| Harvesting credentials in trust negotiation as an honest-but-curious adversary |
| Full text |
Pdf
(129 KB)
|
Source
|
Workshop On Privacy In The Electronic Society
archive
Proceedings of the 2007 ACM workshop on Privacy in electronic society
table of contents
Alexandria, Virginia, USA
SESSION: Short papers
table of contents
Pages: 64 - 67
Year of Publication: 2007
ISBN:978-1-59593-883-1
|
|
Authors
|
|
| Sponsors |
|
| Publisher |
|
| Bibliometrics |
Downloads (6 Weeks): 2, Downloads (12 Months): 34, Citation Count: 0
|
|
|
ABSTRACT
Need-to-know is a fundamental security concept: a party should not learn information that is irrelevant to its mission. In this paper we show that during a trust negotiation in which parties show their credentials to one another, an adversary can systematically harvest information about all of a victim's credentials that the attacker is entitled to see, regardless of their relevance to the negotiation. We present examples of need-to-know attacks with the trust negotiation approaches proposed Yu, Winslett, and Seamons; by Bonatti and Samarati; and by Winsborough and Li. Finally, we propose possible countermeasures against need-to-know attacks, and discuss their advantages and disadvantages.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
| |
1
|
|
| |
2
|
|
 |
3
|
|
 |
4
|
|
 |
5
|
|
| |
6
|
J. Li and N. Li, "OACerts: Oblivious Attribute Certificates," Conference on Applied Cryptography and Network Security, New York, NY, Jun. 2005.
|
| |
7
|
J. Li, N. Li, and W. H. Winsborough, "Automated Trust Negotiation Using Cryptographic Credentials," to appear in Transactions on Information and System Security, 2007.
|
 |
8
|
|
| |
9
|
L. E. Olson, M. J. Rosulek, and M. Winslett, "A Generalized Honest-But-Curious Strategy for Automatically Harvesting Credentials," Technical Report UIUCDCS-R-2007-2892, Department of Computer Science, University of Illinois, Aug. 2007.
|
 |
10
|
Tatyana Ryutov , Li Zhou , Clifford Neuman , Travis Leithead , Kent E. Seamons, Adaptive trust negotiation and access control, Proceedings of the tenth ACM symposium on Access control models and technologies, June 01-03, 2005, Stockholm, Sweden
[doi> 10.1145/1063979.1064004]
|
| |
11
|
|
 |
12
|
|
|