loading...
Secure Context-Sensitive Authorization
Kauai Island, Hawaii March 08-March 12
DOI Bookmark: http://doi.ieeecomputersociety.org/10.1109/PERCOM.2005.37Third IEEE International Conference o ...
 This Article 
 
PDF
HTML
 
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
Kazuhiro Minami, Dartmouth College
David Kotz, Dartmouth College
There is a recent trend toward rule-based authorization systems to achieve flexible security policies. Also, new sensing technologies in pervasive computing make it possible to define context-sensitive rules, such as "allow database access only to staff who are currently located in the main office." However, these rules, or the facts that are needed to verify authority, often involve sensitive context information. This paper presents a secure context-sensitive authorization system that protects confidential information in facts or rules. Furthermore, our system allows multiple hosts in a distributed environment to perform the evaluation of an authorization query in a collaborative way; we do not need a universally trusted central host that maintains all the context information. The core of our approach is to decompose a proof for making an authorization decision into a set of sub-proofs produced on multiple different hosts, while preserving the integrity and confidentiality policies of the mutually untrusted principals operating these hosts.
Citation:
Kazuhiro Minami, David Kotz, "Secure Context-Sensitive Authorization," percom, pp.257-268, Third IEEE International Conference on Pervasive Computing and Communications (PerCom'05), 2005
Usage of this product signifies your acceptance of the Terms of Use.