ACM Home Page
Please provide us with feedback. Feedback
Harvesting credentials in trust negotiation as an honest-but-curious adversary
Full text PdfPdf (129 KB)
Source
Workshop On Privacy In The Electronic Society archive
Proceedings of the 2007 ACM workshop on Privacy in electronic society table of contents
Alexandria, Virginia, USA
SESSION: Short papers table of contents
Pages: 64 - 67  
Year of Publication: 2007
ISBN:978-1-59593-883-1
Authors
Lars E. Olson  University of Illinois at Urbana-Champaign, Urbana, IL
Michael J. Rosulek  University of Illinois at Urbana-Champaign, Urbana, IL
Marianne Winslett  University of Illinois at Urbana-Champaign, Urbana, IL
Sponsors
SIGSAC: ACM Special Interest Group on Security, Audit, and Control
ACM: Association for Computing Machinery
Publisher
ACM  New York, NY, USA
Bibliometrics
Downloads (6 Weeks): 2,   Downloads (12 Months): 34,   Citation Count: 0
Additional Information:

abstract   references   index terms   collaborative colleagues  

Tools and Actions: Request Permissions Request Permissions    Review this Article  
DOI Bookmark: Use this link to bookmark this Article: http://doi.acm.org/10.1145/1314333.1314345
What is a DOI?

ABSTRACT

Need-to-know is a fundamental security concept: a party should not learn information that is irrelevant to its mission. In this paper we show that during a trust negotiation in which parties show their credentials to one another, an adversary can systematically harvest information about all of a victim's credentials that the attacker is entitled to see, regardless of their relevance to the negotiation. We present examples of need-to-know attacks with the trust negotiation approaches proposed Yu, Winslett, and Seamons; by Bonatti and Samarati; and by Winsborough and Li. Finally, we propose possible countermeasures against need-to-know attacks, and discuss their advantages and disadvantages.


REFERENCES

Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.

 
1
 
2
3
4
5
 
6
J. Li and N. Li, "OACerts: Oblivious Attribute Certificates," Conference on Applied Cryptography and Network Security, New York, NY, Jun. 2005.
 
7
J. Li, N. Li, and W. H. Winsborough, "Automated Trust Negotiation Using Cryptographic Credentials," to appear in Transactions on Information and System Security, 2007.
8
 
9
L. E. Olson, M. J. Rosulek, and M. Winslett, "A Generalized Honest-But-Curious Strategy for Automatically Harvesting Credentials," Technical Report UIUCDCS-R-2007-2892, Department of Computer Science, University of Illinois, Aug. 2007.
10
 
11
12

Collaborative Colleagues:
Lars E. Olson: colleagues
Michael J. Rosulek: colleagues
Marianne Winslett: colleagues