DocumentCode :
3040349
Title :
AttributeTrust A Framework for Evaluating Trust in Aggregated Attributes via a Reputation System
Author :
Mohan, Apurva ; Blough, Douglas M.
Author_Institution :
Sch. of Electr. & Comput. Eng., Georgia Inst. of Technol., Atlanta, GA
fYear :
2008
fDate :
1-3 Oct. 2008
Firstpage :
201
Lastpage :
212
Abstract :
To enable a rich attribute-based authorization system, it is desirable that a large number of user attributes are available, possibly provided by multiple entities. The user may be required to aggregate his attributes and present them to a service provider to prove he has the right to access some service. In this paper, we present AttributeTrust - a policy-based privacy enhanced framework for aggregating user attributes and evaluating confidence in these attributes. We envision a future where attribute providers will be commonplace and service providers will face the problem of choosing one among multiple attribute providers that can provide the same user attribute. In AttributeTrust, we address this problem by means of a reputation system model based on transitive trust. Entities express confidence in other entities to supply trusted attributes, forming chains from a service provider to different attribute providers. A service provider uses this transitive reputation to decide whether to accept a particular attribute from a specific attribute provider.We discuss how the AttributeTrust model prevents common attacks on reputation systems. AttributeTrust differs from the current approaches by deriving its attack resistance from its specific context of attribute provisioning, its voting mechanism formulation, and unique properties of its confidence relationships.
Keywords :
authorisation; data privacy; AttributeTrust; aggregated attributes; attack resistance; attribute provisioning; attribute-based authorization system; confidence relationship properties; policy-based privacy enhanced framework; reputation system; transitive reputation; transitive trust; voting mechanism formulation; Access control; Aggregates; Authorization; Certification; Computer security; Databases; Mechanical factors; Privacy; Public key; Voting; Attribute Aggregation; Privacy; Reputation System; Transitive Trust; Trust Negotiation;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Privacy, Security and Trust, 2008. PST '08. Sixth Annual Conference on
Conference_Location :
Fredericton, NB
Print_ISBN :
978-0-7695-3390-2
Type :
conf
DOI :
10.1109/PST.2008.28
Filename :
4641287
Link To Document :
بازگشت