Privacy-Preserving Enforcement of Spatially Aware RBAC

被引:11
|
作者
Kirkpatrick, Michael S. [1 ]
Ghinita, Gabriel [2 ]
Bertino, Elisa [3 ]
机构
[1] James Madison Univ, Dept Comp Sci, Harrisonburg, VA 22807 USA
[2] Univ Massachusetts, Dept Comp Sci, Boston, MA 02125 USA
[3] Purdue Univ, Dept Comp Sci, W Lafayette, IN 47907 USA
关键词
RBAC; privacy; security; access control; applied cryptography; INFORMATION-RETRIEVAL; ACCESS-CONTROL; PROTOCOL;
D O I
10.1109/TDSC.2011.62
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Several models for incorporating spatial constraints into role-based access control (RBAC) have been proposed, and researchers are now focusing on the challenge of ensuring such policies are enforced correctly. However, existing approaches have a major shortcoming, as they assume the server is trustworthy and require complete disclosure of sensitive location information by the user. In this work, we propose a novel framework and a set of protocols to solve this problem. Specifically, in our scheme, a user provides a service provider with role and location tokens along with a request. The service provider consults with a role authority and a location authority to verify the tokens and evaluate the policy. However, none of the servers learn the requesting user's identity, role, or location. In this paper, we define the protocols and the policy enforcement scheme, and present a formal proof of a number of security properties.
引用
收藏
页码:627 / 640
页数:14
相关论文
共 50 条
  • [31] Location-Aware and Privacy-Preserving Data Cleaning for Intelligent Transportation
    Wang, Yuqing
    Zhang, Junwei
    Ma, Zhuo
    Lu, Ning
    Li, Teng
    Ma, Jianfeng
    IEEE TRANSACTIONS ON INTELLIGENT TRANSPORTATION SYSTEMS, 2024, 25 (12) : 20405 - 20418
  • [32] A Fairness-Aware and Privacy-Preserving Online Insurance Application System
    Zhang, Aiqing
    Bacchus, Abel
    Lin, Xiaodong
    2016 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2016,
  • [33] A Privacy-Preserving Time-Aware Method for Next POI Recommendation
    Fan, Jianyong
    Pan, Chenxi
    Geng, Yue
    Li, Shuyu
    ELECTRONICS, 2023, 12 (15)
  • [34] Spatiotemporal-Aware Privacy-Preserving Task Matching in Mobile Crowdsensing
    Peng, Tao
    Zhong, Wentao
    Wang, Guojun
    Zhang, Shaobo
    Luo, Entao
    Wang, Tian
    IEEE INTERNET OF THINGS JOURNAL, 2024, 11 (02) : 2394 - 2406
  • [35] Latency-aware Privacy-preserving Service Migration in Federated Edges
    Souza, Paulo
    Crestani, Angelo
    Rubin, Felipe
    Ferreto, Tiago
    Rossi, Fabio
    PROCEEDINGS OF THE 12TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING AND SERVICES SCIENCE (CLOSER), 2022, : 288 - 295
  • [36] An information-aware visualization for privacy-preserving accelerometer data sharing
    Xiao, Fengjun
    Lu, Mingming
    Zhao, Ying
    Menasria, Soumia
    Meng, Dan
    Xie, Shangsheng
    Li, Juncai
    Li, Chengzhi
    HUMAN-CENTRIC COMPUTING AND INFORMATION SCIENCES, 2018, 8
  • [37] Lightweight Privacy-Preserving Task Assignment in Skill-Aware Crowdsourcing
    Beziaud, Louis
    Allard, Tristan
    Gross-Amblard, David
    DATABASE AND EXPERT SYSTEMS APPLICATIONS, DEXA 2017, PT II, 2017, 10439 : 18 - 26
  • [38] Context-aware privacy-preserving access control for mobile computing
    Herrera, Juan Luis
    Chen, Hsiao-Yuan
    Berrocal, Javier
    Murillo, Juan M.
    Julien, Christine
    PERVASIVE AND MOBILE COMPUTING, 2022, 87
  • [39] FedKGRec: privacy-preserving federated knowledge graph aware recommender system
    Ma, Xiao
    Zhang, Hongyu
    Zeng, Jiangfeng
    Duan, Yiqi
    Wen, Xuan
    APPLIED INTELLIGENCE, 2024, 54 (19) : 9028 - 9044
  • [40] Human-Factor-Aware Privacy-Preserving Aggregation in Smart Grid
    Jia, Weiwei
    Zhu, Haojin
    Cao, Zhenfu
    Dong, Xiaolei
    Xiao, Chengxin
    IEEE SYSTEMS JOURNAL, 2014, 8 (02): : 598 - 607