Sciweavers

WPES
2005
ACM

Anonymous yet accountable access control

13 years 10 months ago
Anonymous yet accountable access control
This paper introduces a novel approach for augmenting attributebased access control systems in a way that allows them to offer fully anonymous access to resources while at the same time achieving strong accountability guarantees. We assume that users hold attribute certificates and we show how to exploit cryptographic zeroknowledge proofs to allow requesting users to prove that they hold suitable certificates for accessing a resource. In contrast to the commonly taken approach of sending all possibly relevant certificates to the access control system, our approach hence does not release any information to the access control system except for the presence of a set of certificates satisfying the access condition. This constitutes the minimal amount of information that has to be released for coming up with a correct access decision, and our approach is the first to achieve this. Additionally given a trusted third party for identity escrow, we furthermore show that a concise applicat...
Michael Backes, Jan Camenisch, Dieter Sommer
Added 26 Jun 2010
Updated 26 Jun 2010
Type Conference
Year 2005
Where WPES
Authors Michael Backes, Jan Camenisch, Dieter Sommer
Comments (0)