A Card Requirements Language Enabling Privacy-Preserving Access Control

被引:7
|
作者
Camenisch, Jan [1 ]
Moedersheim, Sebastian [1 ]
Neven, Gregory [1 ]
Preiss, Franz-Stefan [1 ]
Sommer, Dieter [1 ]
机构
[1] IBM Res Zurich, Zurich, Switzerland
关键词
Access Control; Policy Languages; Privacy; Anonymous Credentials; Digital Credentials;
D O I
10.1145/1809842.1809863
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
We address the problem of privacy-preserving access control in distributed systems. Users commonly reveal more personal data than strictly necessary to be granted access to online resources, even though existing technologies, such as anonymous credential systems, offer functionalities that would allow for privacy-friendly authorization. An important reason for this lack of technology adoption is, as we believe, the absence of a suitable authorization language offering adequate expressiveness to address the privacy-friendly functionalities. To overcome this problem, we propose an authorization language that allows for expressing access control requirements in a privacy-preserving way. Our language is independent from concrete technology, thus it allows for specifying requirements regardless of implementation details while it is also applicable for technologies designed without privacy considerations. We see our proposal as an important step towards making access control systems privacy-preserving.
引用
收藏
页码:119 / 128
页数:10
相关论文
共 50 条
  • [1] Enabling Privacy-Preserving Data Sharing with Bilateral Access Control for Cloud
    Wu, Tong
    Ma, Xiaochen
    Yan, Hailun
    ELECTRONICS, 2023, 12 (23)
  • [2] Enabling Efficient and Privacy-Preserving Task Allocation with Temporal Access Control for Mobile Crowdsensing
    Song, Fuyuan
    Liu, Yiwei
    Ma, Siyao
    Jiang, Qin
    Zhang, Xiang
    Fu, Zhangjie
    ELECTRONICS, 2023, 12 (14)
  • [3] Privacy-Preserving Access Control in Cloud Federations
    Alansari, Shorouq
    Paci, Federica
    Margheri, Andrea
    Sassone, Vladimiro
    2017 IEEE 10TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING (CLOUD), 2017, : 757 - 760
  • [4] Privacy-Preserving Face Recognition for Access Control Systems
    Zhang, Sucan
    Ma, Jianfei
    Zhang, Mingxuan
    Hua, Jingyu
    2024 IEEE 21ST INTERNATIONAL CONFERENCE ON MOBILE AD-HOC AND SMART SYSTEMS, MASS 2024, 2024, : 348 - 356
  • [5] Privacy-Preserving Distributed Data Access Control for CloudIoT
    Nasiraee, Hassan
    Ashouri-Talouki, Maede
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2022, 19 (04) : 2476 - 2487
  • [6] To pass or not to pass: Privacy-preserving physical access control
    Garcia-Rodriguez, Jesus
    Krenn, Stephan
    Slamanig, Daniel
    COMPUTERS & SECURITY, 2024, 136
  • [7] A survey of privacy-preserving access control in cloud computing
    Li, Hongjiao, 1600, Binary Information Press (10):
  • [8] ACCESS CONTROL FOR PRIVACY-PRESERVING GAUSSIAN PROCESS REGRESSION
    Nakachi, Takayuki
    Wang, Yitu
    2022 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH AND SIGNAL PROCESSING (ICASSP), 2022, : 4158 - 4162
  • [9] Towards Distributed Privacy-Preserving Mobile Access Control
    Wang, Zhijie
    Huang, Dijiang
    Wu, Huijun
    Li, Bing
    Deng, Yuli
    2014 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM 2014), 2014, : 582 - 587
  • [10] Distributed Privacy-Preserving Access Control in Sensor Networks
    Zhang, Rui
    Zhang, Yanchao
    Ren, Kui
    IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2012, 23 (08) : 1427 - 1438