Trusted Decentralized Access Control for Client-Context Privacy Preservation

Han Weili,Gao Jun,Chen Chen
2009-01-01
Journal of Computer-Aided Design & Computer Graphics
Abstract:Privacy preservation is a hotspot in the access control research field. This paper proposes a novel access control mechanism,named trusted decentralized access control (TDAC). TDAC includes two reference monitors: private trusted reference monitor and master reference monitor. The former leverages trusted computing technologies at the client side,credibly evaluates access control requests and signs temporary access control credentials. The latter runs at the server side,evaluates the access control requests according to temporary access control credentials only. TDAC can solve the issue of privacy preservation in client-context aware access control,because no local private context data except for temporary access control credentials leak from the client side to the server side during the access control evaluation. In addition,TDAC can reduce the burden of a server to fetch subject-context data. The paper also proposes an architecture to implement TDAC for client-context aware access control,and applies TDAC to simple location aware role based access control. Finally,the security analysis and the performance evaluation show that TDAC can effectively implement privacy preservation.
What problem does this paper attempt to address?