k-anonymous attribute-based access control
Anna Squicciarini, Alberto Trombetta, Elisa Bertino, Abhilasha Bhargav-Spantzel · International Conference on Information and Communication Security · 2007
Access control in a distributed system can be achieved by requesting digital credentials of the entity wanting to access the system. Credentials contain attributes that attest information concerning a given subject. Because such information can be sensitive, uncontrolled disclosure of such sensitive attributes may result in privacy breaches. Previous research efforts have shown that, even if one discloses only non-sensitive attributes, these attributes can still be linked to specific individuals. In this work, we propose attribute-based authorizations to satisfy the kanonymity property: the set of credentials submitted by a subject during an access control operation should be equal to at least k other such sets received by the counterpart during earlier access controls operations. We thus propose a protocol that ensures k-anonymity for users accessing services in a distributed setting. Our protocol has a number of important features. First, anonymity is user-centric, in that anonymity degree k is defined by the credential submitter itself. A credential submitter before submitting its set of credentials has the assurance that its set will be identical to at least k other sets already stored at the counterpart. This assurance is provided in a privacy-preserving fashion, so that no actual information is leaked about the two negotiating parties data used to build such knowledge. Second, we provide a cryptographic protocol ensuring that the credentials submitted by the submitter during different transactions cannot be linked to each other. Third, we ensure that the critical data exchanged during the protocol are valid.