loading...
 This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
2006 IEEE/WIC/ACM International Conferences on Web Intelligence and Intelligent Agent Technology - Workshops
Trust Negotiations with Customizable Anonymity
Hong Kong, China
December 18-December 22
ISBN: 0-7695-2749-3
Anna Cinzia Squicciarini, Purdue University, USA
Abhilasha Barghav-Spantzel, Purdue University, USA
Elisa Bertino, Purdue University, USA
Elena Ferrari, University of Insubria at Como, Italy
Indrakshi Ray, Colorado State University, USA
Trust negotiation makes it possible for two parties to carry on secure transactions by first establishing trust through a bilateral, iterative process of requesting and disclosing digital credentials and policies. Credentials, exchanged during trust negotiations, often contain sensitive attributes that attest to the properties of the credential owner. Uncontrolled disclosure of such sensitive attributes may cause grave damage to the credential owner. Research has shown that disclosing non-sensitive attributes only can cause identity to be revealed as well. Consequently, we impose a stronger requirement: our negotiations should have the k-anonymity property -- the set of credentials submitted by a subject during a negotiation should be equal to k other such sets received by the counterpart during earlier negotiations. In this paper we propose a protocol that ensures k-anonymity. Our protocol has a number of important features. First, a credential submitter before submitting its set of credentials has the assurance that its set will be identical to k other sets already stored with the counterpart. Second, we provide a cryptographic protocol ensuring that the credentials submitted by the submitter during different negotiations cannot be linked to each other. Third, we ensure that the critical data exchanged during the protocol is valid. Fourth, the major part of the protocol involves the negotiating parties only; the protocol invokes the validator only only when some critical information needs to be validated.
Citation:
Anna Cinzia Squicciarini, Abhilasha Barghav-Spantzel, Elisa Bertino, Elena Ferrari, Indrakshi Ray, "Trust Negotiations with Customizable Anonymity," wi-iatw, pp.69-72, 2006 IEEE/WIC/ACM International Conferences on Web Intelligence and Intelligent Agent Technology - Workshops, 2006
Usage of this product signifies your acceptance of the Terms of Use.