An interactive trust management and negotiation scheme

H. Koshutanski, F. Massacci

Research output: Chapter in Book / Report / Conference proceedingConference contributionAcademicpeer-review

Abstract

Interactive access control allows a server to compute on the fly missing credentials needed to grant access and to adapt its responses on the basis of client's presented and declined credentials. Yet, it may disclose too much information on what credentials a client needs. Automated trust negotiation allows for a controlled disclosure on what credentials a client has during a mutual disclosure process. Yet, it requires pre-arranged policies and sophisticated strategies. How do we bootstrap from simple security policies a comprehensive interactive trust management and negotiation scheme that combines the best of both worlds without their limitations? This is the subject of the paper. © 2005 by International Federation for Information Processing.
Original languageEnglish
Title of host publicationFormal Aspects in Security and Trust - IFIP TC1 WG1.7 Workshop on Formal Aspects in Security and Trust and World Computer Congress, FAST 2004
PublisherSpringer New York LLC
Pages115-128
DOIs
Publication statusPublished - 2005
Externally publishedYes
EventIFIP TC1 WG1.7 2nd International Workshop on Formal Aspects in Security and Trust, FAST 2004 - , France
Duration: 22 Aug 200427 Aug 2004

Publication series

NameIFIP Advances in Information and Communication Technology
ISSN (Print)1868-4238

Conference

ConferenceIFIP TC1 WG1.7 2nd International Workshop on Formal Aspects in Security and Trust, FAST 2004
Country/TerritoryFrance
Period22/08/0427/08/04

Fingerprint

Dive into the research topics of 'An interactive trust management and negotiation scheme'. Together they form a unique fingerprint.

Cite this