Privacy-Preserving Enforcement of Spatially Aware RBAC

被引:11
|
作者
Kirkpatrick, Michael S. [1 ]
Ghinita, Gabriel [2 ]
Bertino, Elisa [3 ]
机构
[1] James Madison Univ, Dept Comp Sci, Harrisonburg, VA 22807 USA
[2] Univ Massachusetts, Dept Comp Sci, Boston, MA 02125 USA
[3] Purdue Univ, Dept Comp Sci, W Lafayette, IN 47907 USA
关键词
RBAC; privacy; security; access control; applied cryptography; INFORMATION-RETRIEVAL; ACCESS-CONTROL; PROTOCOL;
D O I
10.1109/TDSC.2011.62
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Several models for incorporating spatial constraints into role-based access control (RBAC) have been proposed, and researchers are now focusing on the challenge of ensuring such policies are enforced correctly. However, existing approaches have a major shortcoming, as they assume the server is trustworthy and require complete disclosure of sensitive location information by the user. In this work, we propose a novel framework and a set of protocols to solve this problem. Specifically, in our scheme, a user provides a service provider with role and location tokens along with a request. The service provider consults with a role authority and a location authority to verify the tokens and evaluate the policy. However, none of the servers learn the requesting user's identity, role, or location. In this paper, we define the protocols and the policy enforcement scheme, and present a formal proof of a number of security properties.
引用
收藏
页码:627 / 640
页数:14
相关论文
共 50 条
  • [41] Privacy-Preserving Task Assignment in Skill-Aware Spatial Crowdsourcing
    Ye, Hang
    Han, Kai
    Xu, Ke
    Gao, Feng
    Xu, Chaoting
    WIRELESS ALGORITHMS, SYSTEMS, AND APPLICATIONS (WASA 2018), 2018, 10874 : 593 - 605
  • [42] PrivaSense: Privacy-Preserving and Reputation-Aware Mobile Participatory Sensing
    Mousa, Hayam
    Ben Mokhtar, Sonia
    Hasan, Omar
    Brunie, Lionel
    Younes, Osama
    Hadhoud, Mohiy
    PROCEEDINGS OF THE 14TH EAI INTERNATIONAL CONFERENCE ON MOBILE AND UBIQUITOUS SYSTEMS: COMPUTING, NETWORKING AND SERVICES (MOBIQUITOUS 2017), 2017, : 38 - 47
  • [43] A Privacy-Preserving Infrastructure for Driver's Reputation Aware Automotive Services
    Costantino, Gianpiero
    Martinelli, Fabio
    Matteucci, Ilaria
    Santi, Paolo
    SOCIO-TECHNICAL ASPECTS IN SECURITY AND TRUST, STAST 2019, 2021, 11739 : 159 - 174
  • [44] Security-Aware and Privacy-Preserving Communication in the Internet of Things: A Review
    Priya, J.
    Gunasekaran, M.
    2019 5TH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING & COMMUNICATION SYSTEMS (ICACCS), 2019, : 225 - 230
  • [45] Towards intent-aware and privacy-preserving image processing systems
    ODonnell, Jake
    Tan, Jason
    Mihailescu, Radu-Casian
    COMPANION PROCEEDINGS OF THE 10TH INTERNATIONAL CONFERENCE ON THE INTERNET OF THINGS, IOT 2020, 2020,
  • [46] Privacy-preserving SVANETs Privacy-preserving Simple Vehicular Ad-hoc Networks
    Hajny, Jan
    Malina, Lukas
    Martinasek, Zdenek
    Zeman, Vaclav
    PROCEEDINGS OF THE 10TH INTERNATIONAL CONFERENCE ON SECURITY AND CRYPTOGRAPHY (SECRYPT 2013), 2013, : 267 - 274
  • [47] RoPriv: Road Network-Aware Privacy-Preserving Framework in Spatial Crowdsourcing
    Wang, Mengyuan
    Jiang, Hongbo
    Zhao, Ping
    Li, Jie
    Liu, Jiangchuan
    Min, Geyong
    Dustdar, Schahram
    IEEE TRANSACTIONS ON MOBILE COMPUTING, 2024, 23 (03) : 2351 - 2366
  • [48] Mobility-Aware Differentially Private Trajectory for Privacy-Preserving Continual Crowdsourcing
    Qiu, Guoying
    Shen, Yulong
    IEEE Access, 2021, 9 : 26362 - 26376
  • [49] Privacy-preserving and Utility-aware Participant Selection for Mobile Crowd Sensing
    Shanila Azhar
    Shan Chang
    Ye Liu
    Yuting Tao
    Guohua Liu
    Mobile Networks and Applications, 2022, 27 : 290 - 302
  • [50] Towards fairness-aware and privacy-preserving enhanced collaborative learning for healthcare
    Zhang, Feilong
    Zhai, Deming
    Bai, Guo
    Jiang, Junjun
    Ye, Qixiang
    Ji, Xiangyang
    Liu, Xianming
    NATURE COMMUNICATIONS, 2025, 16 (01)