Guaranteeing Anonymity in Attribute-Based Authorization
Erin Lanus, Charles J. Colbourn, Gail-Joon Ahn

TL;DR
This paper introduces anonymizing arrays to ensure strong anonymity guarantees in attribute-based authorization systems, addressing the attribute distribution problem that can compromise user anonymity.
Contribution
It proposes the use of anonymizing arrays to guarantee anonymity in attribute-based access control, along with metrics for comparing array homogeneity.
Findings
Anonymizing arrays can ensure that any attribute combination appears at least r times.
Metrics for local and global homogeneity help compare anonymizing arrays.
The approach addresses the attribute distribution problem in anonymous authorization.
Abstract
Attribute-based methods, such as attribute-based access control and attribute-based encryption, make decisions based on attributes possessed by a subject rather than the subject's identity. While this allows for anonymous authorization -- determining that a subject is authorized without knowing the identity of the subject -- it does not guarantee anonymity. If a policy can be composed such that few subjects possess attributes satisfying the policy, then when the policy is used for access control, in addition to making a grant or deny decision, the system can also guess with high probability the identity of the subject making the request. Other approaches to achieving anonymity in attribute-based authorization do not address this attribute distribution problem. Suppose polices contain conjunctions of at most attributes and the system must not be able to guess with probability greater…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsPrivacy-Preserving Technologies in Data · Cryptography and Data Security · Internet Traffic Analysis and Secure E-voting
