ACM Home Page
Please provide us with feedback. Feedback
Minimal credential disclosure in trust negotiations
Full text PdfPdf (604 KB)
Source
Conference on Computer and Communications Security archive
Proceedings of the 4th ACM workshop on Digital identity management table of contents
Alexandria, Virginia, USA
SESSION: Discovery and negotiation table of contents
Pages 89-96  
Year of Publication: 2008
ISBN:978-1-60558-294-8
Authors
Federica Paci  Purdue University, West Lafayette, IN, USA
David Bauer  Georgia Institute of Technology, Atlanta, GA, USA
Elisa Bertino  Purdue University, West Lafayette, IN, USA
Douglas M. Blough  Georgia Institute of Technology, West Lafayette, IN, USA
Anna Squicciarini  The Pennsylvania State University, University Park, PA, USA
Sponsors
SIGSAC: ACM Special Interest Group on Security, Audit, and Control
ACM: Association for Computing Machinery
Publisher
ACM  New York, NY, USA
Bibliometrics
Downloads (6 Weeks): 15,   Downloads (12 Months): 143,   Citation Count: 0
Additional Information:

abstract   references   index terms   collaborative colleagues  

Tools and Actions: Request Permissions Request Permissions    Review this Article  
DOI Bookmark: Use this link to bookmark this Article: http://doi.acm.org/10.1145/1456424.1456439
What is a DOI?

ABSTRACT

The secure release of identity attributes is a key enabler for electronic business interactions. Integrity and confidentiality of identity attributes are two key requirements in such context. Users should also have the maximum control possible over the release of their identity attributes and should state under which conditions these attributes can be disclosed. Moreover, users should disclose only the identity attributes that are actually required for the transactions at hand. In this paper we present an approach for the controlled release of identity attributes that addresses such requirements. The approach is based on the integration of trust negotiation and minimal credential disclosure techniques. Trust negotiation supports selective and incremental disclosure of identity attributes, while minimal credential disclosure guarantees that only the attributes necessary to complete the on line interactions are disclosed.


REFERENCES

Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.

1
 
2
 
3
S. Brands, Credentica -- u-prove sdk, 2007.
4
5
6
 
7
R.D. Jarvis, Selective Disclosure of Credential Content during Trust Negotiation, Master of Science Thesis, Brigham Young University, Provo, Utah, April 2003.
 
8
 
9
A. Hess, J. Jacobson, H. Mills, R. Wamsley, K. E. Seamons, B. Smith, Advanced Client/Server Authentication in TLS, In Proceedings of Network and Distributed System Security Symposium, San Diego, CA, February 2002.
10
 
11
12
13
 
14
J. Li and N. Li, Oacerts: Oblivious attribute certificates. In John Ioannidis, Angelos D. Keromytis, and Moti Yung, editors, ACNS, volume 3531 of Lecture Notes in Computer Science, pp. 301--317, 2005.
 
15
16
 
17
K. E. Seamons, M. Winslett and T. Yu, Limiting the disclosure of Access Control Policies during Automated Trust Negotiation, In Proceedings of Network and Distributed System Security Simposium, San Diego, CA, February 2001.
 
18
 
19
W. H. Winsborough, K. E. Seamons, V. Jones, Automated Trust Negotiation, DARPA Information Survivability Conference and Exposition, Volume I, pp. 88--102, IEEE Press, January 2000.
20
 
21
W. H. Winsborough and N. Li, Safety in Automated Trust Negotiation, IEEE Symposium on Security and Privacy, Oakland, CA, May 2004.
 
22
WordNet, http://wordnet.princeton.edu/.
 
23
24

Collaborative Colleagues:
Federica Paci: colleagues
David Bauer: colleagues
Elisa Bertino: colleagues
Douglas M. Blough: colleagues
Anna Squicciarini: colleagues