Role Based Authorization as a Tool for Privacy and Anonymity
Douglas Sicker · SSRN Electronic Journal · 2003
The advent of the information age has brought a proliferation in the amount of information that is available and an increase in accessibility to such information. As we rely more heavily on networks as a means of communicating, we must increasingly consider how these networks store and distribute this information. Aside from the problems that arise in managing the security of large diverse systems, we must also consider the implications of distributing personally identifiable information across such systems. For example, both web browsing and voice over internet communications processes include considerable amounts of personally identifiable information about the user. For some, the distribution of (and access to) this personal information is of no consequence; however, for others, this is tantamount to an invasion of their privacy. Some of the issues associated with the distribution of this information arise out of the identity, authentication and authorization models that have been defined for these services. Many of the existing models rely heavily on identity information that readily links back to an individual (i.e., an individual’s name as their login). Further, many models do not provide support for privacy or anonymity, nor do they provide granularity