| The HP time vault service: exploiting IBE for timed release of confidential information |
| Full text |
Pdf
(861 KB)
|
| Source
|
International World Wide Web Conference
archive
Proceedings of the 12th international conference on World Wide Web
table of contents
Budapest, Hungary
SESSION: Data integrity
table of contents
Pages: 160 - 169
Year of Publication: 2003
ISBN:1-58113-680-3
|
|
Authors
|
|
| Sponsor |
|
| Publisher |
|
| Bibliometrics |
Downloads (6 Weeks): n/a, Downloads (12 Months): n/a, Citation Count: 4
|
|
|
ABSTRACT
Digital information is increasingly more and more important to enable interactions and transactions on the Internet. On the other hand, leakages of sensitive information can have harmful effects for people, enterprises and governments.This paper focuses on the problems of dealing with timed release of confidential information and simplifying its access once public: it is a common issue in the industry, government and day-to-day life.We introduce the "HP Time Vault Service", based on the emerging Identifier-based Encryption (IBE) cryptography schema. IBE (public) encryption keys specify the disclosure time. These keys are used to encrypt confidential information. An independent time server generates and publishes IBE decryption keys correspondent to the current time, at predefined intervals.We discuss the advantages of this approach against current approaches based on traditional cryptography. A web-service based prototype is described, as a proof of concept.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
| |
1
|
|
| |
2
|
|
| |
3
|
Clark, D. D. and Wilson, D. R. A Comparison of Commercial and Military Computer Security Policies. In IEEE Symposium on Computer Security and Privacy, April 1987.
|
| |
4
|
|
| |
5
|
Diffie, W. and Hellman, M. E. New Directions in Cryptography, 1976.
|
| |
6
|
|
| |
7
|
Frey, G. and Muller, M. and Ruck, H-G. The Tate Pairing and the Discrete Logarithm Applied to Elliptic Curve Cryptosystems. IEM Preprint No. 23, 1998.
|
| |
8
|
Frederick Gallegos , Sandra Senft , Daniel P. Manson, Ph. D. , Carol Gonzales, Information Technology Control and Audit, Second Edition, Auerbach Publications, Boston, MA, 2004
|
| |
9
|
Garay, J. and Jakobsson, M. Timed Release of Standard Digital Signatures. Financial Crypto, 2002.
|
| |
10
|
May, T. C. Timed-release crypto, February 1993.
|
| |
11
|
Microsoft. Microsoft .NET framework. http://www.microsoft.com/net, 2002
|
| |
12
|
National Physical Laboratory. The time signal: PIPS service. http://www.npl.co.uk, UK, 2002.
|
| |
13
|
|
| |
14
|
RSA Laboratories. PKCS# 7: Cryptographic Message Syntax Standard. Version 1.5, 1993.
|
| |
15
|
Sandhu, R. S. and Samarati, P. Access Control: Principles and Practice, IEEE Communications Magazine. pp. 40--48, September 1994.
|
INDEX TERMS
Primary Classification:
E.
Data
E.3
DATA ENCRYPTION
Subjects:
Public key cryptosystems
Additional Classification:
K.
Computing Milieux
K.4
COMPUTERS AND SOCIETY
K.4.4
Electronic Commerce
Subjects:
Security
K.6
MANAGEMENT OF COMPUTING AND INFORMATION SYSTEMS
K.6.5
Security and Protection (D.4.6, K.4.2)
Subjects:
Unauthorized access (e.g., hacking, phreaking)
General Terms:
Algorithms,
Design,
Experimentation,
Management,
Security
Keywords:
disclosure policies,
identifier-based encryption,
privacy,
security,
timed-release,
web service
|