• DocumentCode
    2822571
  • Title

    Protection profiles for remailer mixes. Do the new evaluation criteria help?

  • Author

    Rannenberg, Kai ; Iachello, Giovanni

  • Author_Institution
    Microsoft Res., Cambridge, UK
  • fYear
    2000
  • fDate
    36861
  • Firstpage
    107
  • Lastpage
    118
  • Abstract
    Early IT security evaluation criteria such as the TCSEC and the ITSEC suffered much criticism for their lack of coverage of privacy-related requirements. Recent evaluation criteria, such as the CC and the ISO-ECITS now contain components assigned to privacy. This is a step towards enhanced privacy protection, especially for non-experts. We examined the suitability and use of these components and the criteria as a whole by specifying a number of protection profiles (PPs) for remailer mix networks, as mix networks aim at user anonymity and unobservable message transfer. This contribution reports on the PPs and the experiences gained. It also introduces proposals for improving the criteria that were derived from this work
  • Keywords
    certification; data privacy; electronic mail; information technology; CC; ISO-ECITS; IT security evaluation criteria; ITSEC; TCSEC; evaluation criteria; information technology; privacy protection; privacy-related requirements; protection profiles; remailer mix networks; remailer mixes; unobservable message transfer; user anonymity; Certification; Computer security; IEC standards; ISO standards; Information security; Information technology; Privacy; Proposals; Protection; USA Councils;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Security Applications, 2000. ACSAC '00. 16th Annual Conference
  • Conference_Location
    New Orleans, LA
  • Print_ISBN
    0-7695-0859-6
  • Type

    conf

  • DOI
    10.1109/ACSAC.2000.898864
  • Filename
    898864