Privacy-preserving similarity measurement for access control policies

Eun Ae Cho*, Gabriel Ghinita, Elisa Bertino

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

9 Citations (Scopus)

Abstract

The emergence of global-scale infrastructures for outsourcing data and content to service providers (e.g., cloud computing) creates unprecedented opportunities for data owners to expand their operations and increase their customer base. On the other hand, each data owner (DO) has a certain set of access control policies, which may be different than those of the service providers (SP). Therefore, to enable effective outsourcing, it is important for the DOs to choose SPs with similar access control policies. Several techniques that measure policy similarity have been proposed in previous work, but they assume that policies are publicly accessible. However, in a global-scale environment without well-established relationships of trust, participants may not be willing to reveal their policies to every other stakeholder. Therefore, the need arises to perform policy similarity in a privacy-preserving manner. Specifically, we propose a technique that allows similarity evaluation of encrypted policies. Our technique relies on an existing encryption method for numerical data called asymmetric scalar product-preserving encryption (ASPE). ASPE allows answering of nearest-neighbor queries without the need to reveal the plaintext contents of either the query or the data. We adapt ASPE to support access control policies, and we present a case study of how private policy similarity evaluation is performed within our proposed framework.

Original languageEnglish
Title of host publicationProceedings of the 6th ACM Workshop on Digital Identity Management, DIM '10, Co-located with CCS'10
Pages3-11
Number of pages9
DOIs
Publication statusPublished - 2010
Externally publishedYes
Event6th ACM Workshop on Digital Identity Management, DIM '10, Co-located with CCS'10 - Chicago, IL, United States
Duration: 4 Oct 20108 Oct 2010

Publication series

NameProceedings of the ACM Conference on Computer and Communications Security
ISSN (Print)1543-7221

Conference

Conference6th ACM Workshop on Digital Identity Management, DIM '10, Co-located with CCS'10
Country/TerritoryUnited States
CityChicago, IL
Period4/10/108/10/10

Keywords

  • asymmetric scalar product-preserving encryption (aspe)
  • policy similarity

Fingerprint

Dive into the research topics of 'Privacy-preserving similarity measurement for access control policies'. Together they form a unique fingerprint.

Cite this