DocumentCode :
1478805
Title :
Recommendation Models for Open Authorization
Author :
Shehab, Mohamed ; Marouf, Said
Author_Institution :
Dept. of Software & Inf. Syst., Univ. of North Carolina at Charlotte, Charlotte, NC, USA
Volume :
9
Issue :
4
fYear :
2012
Firstpage :
583
Lastpage :
596
Abstract :
Major online platforms such as Facebook, Google, and Twitter allow third-party applications such as games, and productivity applications access to user online private data. Such accesses must be authorized by users at installation time. The Open Authorization protocol (OAuth) was introduced as a secure and efficient method for authorizing third-party applications without releasing a user´s access credentials. However, OAuth implementations don´t provide the necessary fine-grained access control, nor any recommendations, i.e., which access control decisions are most appropriate. We propose an extension to the OAuth 2.0 authorization that enables the provisioning of fine-grained authorization recommendations to users when granting permissions to third-party applications. We propose a multicriteria recommendation model that utilizes application-based, user-based, and category-based collaborative filtering mechanisms. Our collaborative filtering mechanisms are based on previous user decisions, and application permission requests to enhance the privacy of the overall site´s user population. We implemented our proposed OAuth extension as a browser extension that allows users to easily configure their privacy settings at application installation time, provides recommendations on requested privacy permissions, and collects data regarding user decisions. Our experiments on the collected data indicate that the proposed framework efficiently enhanced the user awareness and privacy related to third-party application authorizations.
Keywords :
authorisation; collaborative filtering; online front-ends; protocols; recommender systems; social networking (online); Facebook; Google; OAuth 2.0 authorization; Twitter; application-based collaborative filtering mechanisms; authorization recommendation model; browser extension; category-based collaborative filtering mechanisms; multicriteria recommendation model; online platforms; open authorization; open authorization protocol; third-party application authorizations; user online private data; user-based collaborative filtering mechanisms; Authorization; Browsers; Collaboration; Electronic mail; Facebook; Privacy; Servers; OAuth; collaborative filtering; social networks.;
fLanguage :
English
Journal_Title :
Dependable and Secure Computing, IEEE Transactions on
Publisher :
ieee
ISSN :
1545-5971
Type :
jour
DOI :
10.1109/TDSC.2012.34
Filename :
6175026
Link To Document :
بازگشت