节点文献
自动信任协商中的推理攻击分析
The Analysis of Inference Attack in Automated Trust Negotiation
【摘要】 自动信任协商是陌生实体通过交替地披露属性证书建立信任关系的一种方法。主体拥有的不同属性之间可能存在着某种联系,某些属性的披露会导致其它敏感信息的泄露,即推理攻击。本文分析了属性间的线性关系,提出了属性敏感强度的概念,定义了属性敏感强度的偏序关系,在此基础上定义了自动信任协商系统抽象模型。针对几类推理攻击给出了相应的防御方案及其安全性分析。
【Abstract】 Automated trust negotiation is an approach to build trust relationship between strangers by disclosing attribute credentials alternately. The attributes owned by principles are always relevant each other, so disclosing some attributes maybe induce leakage of sensitive information, namely inference attack. We give the definition and partial order of sensitivity intensity of private attribute, then an abstract automated trust negotiation model is proposed, which depicts relevancy not only between principles and attributes, but also between policies and attributes. As a result, several inference attacks in automated trust negotiation are discussed, then defense scheme and security analysis are presented.
【Key words】 Credential; Automated trust negotiation; Inference attack; Authorization management;
- 【文献出处】 计算机科学 ,Computer Science , 编辑部邮箱 ,2007年07期
- 【分类号】TP393.08
- 【被引频次】8
- 【下载频次】161