• DocumentCode
    3040349
  • Title

    AttributeTrust A Framework for Evaluating Trust in Aggregated Attributes via a Reputation System

  • Author

    Mohan, Apurva ; Blough, Douglas M.

  • Author_Institution
    Sch. of Electr. & Comput. Eng., Georgia Inst. of Technol., Atlanta, GA
  • fYear
    2008
  • fDate
    1-3 Oct. 2008
  • Firstpage
    201
  • Lastpage
    212
  • Abstract
    To enable a rich attribute-based authorization system, it is desirable that a large number of user attributes are available, possibly provided by multiple entities. The user may be required to aggregate his attributes and present them to a service provider to prove he has the right to access some service. In this paper, we present AttributeTrust - a policy-based privacy enhanced framework for aggregating user attributes and evaluating confidence in these attributes. We envision a future where attribute providers will be commonplace and service providers will face the problem of choosing one among multiple attribute providers that can provide the same user attribute. In AttributeTrust, we address this problem by means of a reputation system model based on transitive trust. Entities express confidence in other entities to supply trusted attributes, forming chains from a service provider to different attribute providers. A service provider uses this transitive reputation to decide whether to accept a particular attribute from a specific attribute provider.We discuss how the AttributeTrust model prevents common attacks on reputation systems. AttributeTrust differs from the current approaches by deriving its attack resistance from its specific context of attribute provisioning, its voting mechanism formulation, and unique properties of its confidence relationships.
  • Keywords
    authorisation; data privacy; AttributeTrust; aggregated attributes; attack resistance; attribute provisioning; attribute-based authorization system; confidence relationship properties; policy-based privacy enhanced framework; reputation system; transitive reputation; transitive trust; voting mechanism formulation; Access control; Aggregates; Authorization; Certification; Computer security; Databases; Mechanical factors; Privacy; Public key; Voting; Attribute Aggregation; Privacy; Reputation System; Transitive Trust; Trust Negotiation;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Privacy, Security and Trust, 2008. PST '08. Sixth Annual Conference on
  • Conference_Location
    Fredericton, NB
  • Print_ISBN
    978-0-7695-3390-2
  • Type

    conf

  • DOI
    10.1109/PST.2008.28
  • Filename
    4641287