节点文献

自动信任协商中的推理攻击分析

The Analysis of Inference Attack in Automated Trust Negotiation

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 杨秋伟洪帆郑明辉廖俊国

【Author】 YANG Qiu-Wei HONG Fan ZHENG Ming-Hui LIAO Jun-Guo (Department of Computer Science, Huazhong University of Science & Technology, Wuhan 430074

【机构】 华中科技大学计算机学院华中科技大学计算机学院 武汉430074武汉430074

【摘要】 自动信任协商是陌生实体通过交替地披露属性证书建立信任关系的一种方法。主体拥有的不同属性之间可能存在着某种联系,某些属性的披露会导致其它敏感信息的泄露,即推理攻击。本文分析了属性间的线性关系,提出了属性敏感强度的概念,定义了属性敏感强度的偏序关系,在此基础上定义了自动信任协商系统抽象模型。针对几类推理攻击给出了相应的防御方案及其安全性分析。

【Abstract】 Automated trust negotiation is an approach to build trust relationship between strangers by disclosing attribute credentials alternately. The attributes owned by principles are always relevant each other, so disclosing some attributes maybe induce leakage of sensitive information, namely inference attack. We give the definition and partial order of sensitivity intensity of private attribute, then an abstract automated trust negotiation model is proposed, which depicts relevancy not only between principles and attributes, but also between policies and attributes. As a result, several inference attacks in automated trust negotiation are discussed, then defense scheme and security analysis are presented.

【基金】 国家自然科学基金(No60403027);湖北省教育厅科学基金(NoQ200629001)资助
  • 【文献出处】 计算机科学 ,Computer Science , 编辑部邮箱 ,2007年07期
  • 【分类号】TP393.08
  • 【被引频次】8
  • 【下载频次】161
节点文献中: 

本文链接的文献网络图示:

本文的引文网络