• DocumentCode
    265690
  • Title

    Towards distributed privacy-preserving mobile access control

  • Author

    Zhijie Wang ; Dijiang Huang ; Huijun Wu ; Bing Li ; Yuli Deng

  • Author_Institution
    Arizona State Univ., Tempe, AZ, USA
  • fYear
    2014
  • fDate
    8-12 Dec. 2014
  • Firstpage
    582
  • Lastpage
    587
  • Abstract
    The mobile marketing is growing exponentially worldwide due to the emerging high speed wireless Internet and the proliferation of smartphones with powerful processors. Consequently, the management of the massive volume of mobile identities has sparked a lot of interest in both industry and academia, as they turn out to be a heavy burden for many mobile application startups. The conventional federated identity management technologies have been developed to delegate the users´ identity tasks across different security domains to reduce the burden over the identity service consumers (i.e., Relying Party). However, they also raises serious security and privacy issues, such as the vulnerability to Single Point of Failure (SPOF) and the privacy leakage with respect to users´ historical access information. To address these issues, we architect a novel Distributed Privacy-preserving Mobile Access Control (DP-MAC) framework. This framework also leverages a dual-root trust model to prevent identity theft in case of mobile device loss. In the end, we give performance evaluation and prove its applicability by implementing our system in the Cloud Computing platform and android smartphones based on jPBC in real-world settings.
  • Keywords
    authorisation; data privacy; marketing; mobile computing; Android smartphones; DP-MAC framework; SPOF; cloud computing platform; distributed privacy-preserving mobile access control; dual-root trust model; federated identity management technology; high speed wireless Internet; identity service consumers; identity theft prevention; jPBC; mobile identity; mobile marketing; privacy leakage; single point of failure; smartphones; user historical access information; Access control; Authentication; Cryptography; Mobile communication; Smart phones;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Global Communications Conference (GLOBECOM), 2014 IEEE
  • Conference_Location
    Austin, TX
  • Type

    conf

  • DOI
    10.1109/GLOCOM.2014.7036870
  • Filename
    7036870