arrow
Return

Guaranteeing anonymity in attribute-based authorization

delete2024-12-01
delete0
PRE
AI
E
Erin Lanus *
C
Charles J. Colbourn
G
Gail‐Joon Ahn
DOI:10.1016/j.jisa.2024.103895delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Attribute-based methods such as attribute-based access control make decisions based on attributes possessed by a subject rather than the subject's identity. This allows for anonymous authorization but does not guarantee anonymity. If a policy can be composed that few subjects possess attributes to satisfy and is used access control, the system can guess with high probability the requesting subject's identity. Other approaches to achieving anonymity in attribute-based authorization do not address this attribute distribution problem. Suppose polices contain conjunctions of at most t attributes and the system must not be able to guess with probability greater than 1 the identity of a subject using a policy for authorization. The anonymity guarantee r is r for maximum credential size t . An anonymizing array is a combinatorial array proposed as an abstraction to address the distribution problem by ensuring that any assignment of values to t attributes appearing the array appears at least r times. Anonymizing arrays are related to covering arrays with higher coverage, but have an additional property, homogeneity, due to their application domain. We discuss the application of anonymizing arrays to guarantee anonymous authorization in attribute-based methods. Additionally, develop metrics to compare arrays with the same parameters.
Keywords:
Attribute-based access control
Attribute-based encryption
Authorization
Anonymity
Combinatorial array

Journal

Journal of Information Security and Applications cover
Journal of Information Security and Applications
IF:
3.7
Papers:
1.9K
Citations:
4.9K

Organization

A
Arizona State University
Scholars:
2.7W
Papers: 2.5W
Citations: 4.2W