Privacy-preserving multi-party access control

Conference Paper (2019)
Author(s)

Mina Sheikhalishahi (Eindhoven University of Technology)

G. Tillem (TU Delft - Cyber Security)

Z. Erkin (TU Delft - Cyber Security)

Nicola Zannone (Eindhoven University of Technology)

Research Group
Cyber Security
DOI related publication
https://doi.org/10.1145/3338498.3358643
More Info
expand_more
Publication Year
2019
Language
English
Research Group
Cyber Security
Pages (from-to)
1-13
ISBN (print)
978-1-4503-6830-8

Abstract

Multi-party access control has been proposed to enable collaborative decision making for the protection of co-owned resources. In particular, multi-party access control aims to reconcile conflicts arising from the evaluation of policies authored by different stakeholders for jointly-managed resources, thus determining whether access to those resources should be granted or not. While providing effective solutions for the protection of co-owned resources, existing approaches do not address the protection of policies themselves, whose disclosure can leak sensitive information about, e.g., the relationships of co-owners with other parties. In this paper, we propose a privacy-preserving multi-party access control mechanism, which preserves the confidentiality of user policies. In particular, we propose secure computation protocols for the evaluation of multi-party policies, based on two privacy-preserving techniques, namely homomorphic encryption and secure function evaluation. An experimental evaluation of our approach shows its practical feasibility in terms of both computation and communication costs.

No files available

Metadata only record. There are no files for this record.