返回
摘要
En 中文
The formal specification of privacy goals in symbolic protocol models has proved to be not quite trivial so far. The most widely used approach in formal methods is based on the static equivalence of frames in the applied pi-calculus, basically asking whether or not the intruder is able to distinguish two given worlds. But then a subtle question emerges: How can we be sure that we have specified all pairs of worlds to properly reflect our intuitive privacy goal? To address this problem, we introduce in this article a novel and declarative way to specify privacy goals, called (alpha, beta)-privacy. This new approach is based on specifying two formulae alpha and beta in first-order logic with Herbrand universes, where alpha reflects the intentionally released information and beta includes the actual cryptographic (technical) messages the intruder can see. Then (alpha,beta)-privacy means that the intruder cannot derive any nontechnical statement from beta that he cannot derive from a already. We describe by a variety of examples how this notion can be used in practice. Even though (alpha, beta)-privacy does not directly contain a notion of distinguishing between worlds, there is a close relationship to static equivalence of frames that we investigate formally. This allows us to justify (and criticize) the specifications that are currently used in verification tools and obtain a decision procedure for a large fragment of (alpha, beta)-privacy.
Keyword:
Privacy
frames
static equivalence
voting
model theory
Herbrand logic
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
A
IF:
2.8
论文数:
293
被引数:
770
机构
引用论文
Normal function of the hypothalamic‐pituitary growth axis in three dwarf Friesian foals三匹矮种弗里生驹下丘脑-垂体生长轴的正常功能
Assessment of Human Intraoral Thermal Sensitivity with Simple Devices in the Clinic: Implications for Orofacial Pain Conditions临床中使用简易设备评估人类口腔内热敏感性的研究:对口腔颌面部疼痛状况的启示

