• DocumentCode
    1823606
  • Title

    Optimizing cost-sensitive trust-negotiation protocols

  • Author

    Chen, Weifeng ; Clarke, Lori ; Kurose, Jim ; Towsley, Don

  • Author_Institution
    Dept. of Comput. Sci., Massachusetts Univ., Amherst, MA, USA
  • Volume
    2
  • fYear
    2005
  • fDate
    13-17 March 2005
  • Firstpage
    1431
  • Abstract
    Trust negotiation is a process that establishes mutual trust by the exchange of digital credentials and/or guiding policies among entities who may have no pre-existing knowledge about each other. Motivated by the desire to disclose as little sensitive information as possible in practice, this paper investigates the problem of minimizing the "cost" of the credentials exchanged by a trust-negotiation protocol. A credential or a policy is assigned a weighted cost, referred to as its sensitivity cost. We formalize an optimization problem, namely the minimum sensitivity cost problem, whose objective is to minimize the total sensitivity costs of the credentials and policies disclosed during trust negotiation. We study the complexity of the minimal sensitivity cost problem and propose algorithms to solve the problem efficiently, for the cases that policies are cost-sensitive and cost-insensitive. A simple finite state machine model of trust-negotiation protocols is presented to model various trust-negotiation protocols, and to provide a quantitative evaluation of the number of exchange rounds needed to achieve a successful negotiation, and the probability of achieving a successful negotiation under various credential disclosure strategies.
  • Keywords
    Internet; authorisation; finite state machines; minimisation; probability; protocols; digital credentials; finite state machine model; guiding policies; minimization; minimum sensitivity cost problem; optimization problem; probability; quantitative evaluation; trust-negotiation protocol; Automata; Computer science; Cost function; Electronic commerce; Employment; Government; Internet; Protocols; Security; Telephony;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    INFOCOM 2005. 24th Annual Joint Conference of the IEEE Computer and Communications Societies. Proceedings IEEE
  • ISSN
    0743-166X
  • Print_ISBN
    0-7803-8968-9
  • Type

    conf

  • DOI
    10.1109/INFCOM.2005.1498369
  • Filename
    1498369