Data minimisation in communication protocols: a formal analysis framework and application to identity management

被引:4
|
作者
Veeningen, Meilof [1 ]
de Weger, Benne [1 ]
Zannone, Nicola [1 ]
机构
[1] Eindhoven Univ Technol, NL-5600 MB Eindhoven, Netherlands
关键词
Privacy; Identity management; Formal methods; Data minimisation; Detectability; Associability; AUTOMATED VERIFICATION; ZERO-KNOWLEDGE; PRIVACY; SECURITY; REQUIREMENTS; SECRECY;
D O I
10.1007/s10207-014-0235-z
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
With the growing amount of personal information exchanged over the Internet, privacy is becoming more and more a concern for users. One of the key principles in protecting privacy is data minimisation. This principle requires that only the minimum amount of information necessary to accomplish a certain goal is collected and processed. "Privacy-enhancing" communication protocols have been proposed to guarantee data minimisation in a wide range of applications. However, currently, there is no satisfactory way to assess and compare the privacy they offer in a precise way: existing analyses are either too informal and high level or specific for one particular system. In this work, we propose a general formal framework to analyse and compare communication protocols with respect to privacy by dataminimisation. Privacy requirements are formalised independent of a particular protocol in terms of the knowledge of (coalitions of) actors in a three-layer model of personal information. These requirements are then verified automatically for particular protocols by computing this knowledge from a description of their communication. We validate our framework in an identity management (IdM) case study. As IdM systems are used more and more to satisfy the increasing need for reliable online identification and authentication, privacy is becoming an increasingly critical issue. We use our framework to analyse and compare four identity management systems. Finally, we discuss the completeness and (re)usability of the proposed framework.
引用
收藏
页码:529 / 569
页数:41
相关论文
共 50 条
  • [1] Data minimisation in communication protocols: a formal analysis framework and application to identity management
    Meilof Veeningen
    Benne de Weger
    Nicola Zannone
    International Journal of Information Security, 2014, 13 : 529 - 569
  • [2] Formal Privacy Analysis of Communication Protocols for Identity Management
    Veeningen, Melia
    de Weger, Benne
    Zannone, Nicola
    INFORMATION SYSTEMS SECURITY, 2011, 7093 : 235 - 249
  • [3] A Framework for Formal Analysis of Anonymous Communication Protocols
    Yang, Ke
    Xiao, Meihua
    SECURITY AND COMMUNICATION NETWORKS, 2022, 2022
  • [4] Towards a formal framework for distributed identity management
    He, JS
    Zhang, R
    WEB TECHNOLOGIES RESEARCH AND DEVELOPMENT - APWEB 2005, 2005, 3399 : 913 - 924
  • [5] Formal description of the SWIFT identity management framework
    Perez, Alejandro
    Lopez, Gabriel
    Canovas, Oscar
    Gomez-Skarmeta, Antonio F.
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF GRID COMPUTING AND ESCIENCE, 2011, 27 (08): : 1113 - 1123
  • [6] A Framework for Formal Analysis of Privacy on SSO Protocols
    Wang, Kailong
    Bai, Guangdong
    Dong, Naipeng
    Dong, Jin Song
    SECURITY AND PRIVACY IN COMMUNICATION NETWORKS, SECURECOMM 2017, 2018, 238 : 763 - 777
  • [7] Application of formal methods for analysis of authentication protocols
    Tiwari, RK
    DISTRIBUTED COMPUTING - IWDC 2004, PROCEEDINGS, 2004, 3326 : 536 - 536
  • [8] A tool framework for generation of application optimized communication protocols
    Burda, R
    Seger, J
    PROCEEDINGS OF THE 3RD ANNUAL COMMUNICATION NETWORKS AND SERVICES RESEARCH CONFERENCE, 2005, : 282 - 286
  • [9] Formal analysis of a probabilistic knowledge communication framework
    Gluz, Joao Carlos
    Viccari, Rosa Maria
    Flores, Cecilia Dias
    Seixas, Louise
    ADVANCES IN ARTIFICIAL INTELLIGENCE - IBERAMIA-SBIA 2006, PROCEEDINGS, 2006, 4140 : 138 - 148
  • [10] A Formal Data-Centric Approach for Passive Testing of Communication Protocols
    Lalanne, Felipe
    Maag, Stephane
    IEEE-ACM TRANSACTIONS ON NETWORKING, 2013, 21 (03) : 788 - 801