• DocumentCode
    2952894
  • Title

    Distributed Enforcement of Unlinkability Policies: Looking Beyond the Chinese Wall

  • Author

    Kapadia, Apu ; Naldurg, Prasad ; Campbell, Roy H.

  • Author_Institution
    Dartmouth Coll., Dartmouth
  • fYear
    2007
  • fDate
    13-15 June 2007
  • Firstpage
    141
  • Lastpage
    150
  • Abstract
    We present a discretionary access control framework that can be used to control a principal´s ability to link information from two or more audit records and compromise a user´s privacy. While the traditional Chinese Wall (CW) access control model is sufficient to enforce this type of unlinkability, in distributed environments CW is inefficient because its semantics requires knowledge of a user´s access history. We propose a restricted version of the CW model in which policies are easy to enforce in a decentralized manner without the need for an access history. Our architecture analyzes system policies for potential linkability conflicts. Users can identify specific threats to their privacy, typically in terms of trusted and untrusted roles in the context of RBAC (role based access control), following which the system attaches automatically generated policy constraints to the audit records. When these constraints are enforced appropriately, they implement unlinkability policies that are provably secure and precise for a fixed protection state. We extend the model with a versioning scheme that can handle evolving protection state, including changing roles and permissions, trading precision to maintain the security of deployed policies.
  • Keywords
    auditing; authorisation; data privacy; distributed processing; user modelling; Chinese Wall; audit records; decentralized manner; discretionary access control framework; distributed enforcement; distributed environments CW; fixed protection state; policy constraints; role based access control; unlinkability policy; user privacy; Access control; Computer science; Context modeling; Distributed databases; History; Joining processes; Laboratories; Law; Privacy; Protection;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Policies for Distributed Systems and Networks, 2007. POLICY '07. Eighth IEEE International Workshop on
  • Conference_Location
    Bologna
  • Print_ISBN
    0-7695-2767-1
  • Type

    conf

  • DOI
    10.1109/POLICY.2007.16
  • Filename
    4262581