Minimum Disclosure as Boolean Optimization: New Results
Alessandro Armando, Angela Contento, Daniele Costa, Marco Maratea · 2012
In advanced credential-based, distributed applications, clients gain ac- cess to sensitive resources by proving possession of some properties to the server. Yet, user's properties (or the combination thereof) may be sensitive and the user may want to minimize their disclosure whenever possible. Given a quantitative estimate of the sensitivity of the properties contained in the credentials, the Min- imum Disclosure (MIN-DISCL) problem is the problem of determining a disclo- sure of information that allows the user to obtain the service, while minimizing the overall sensitivity of the exposed disclosure. Previous work provided a reduc- tion of MIN-DISCL to the Weighted Max-SAT problem and showed the practical viability of the approach through experimentation with the YICES SMT solver. In this paper we present a simplified and optimized problem formulation that leads to much smaller encodings and smaller solving times than the original formula- tion on randomly generated MIN-DISCL problems.