An authorization model for a public key management service
Public key management has received considerable attention from both the research and commercial communities as a useful primitive for secure electronic commerce and secure communication. While the mechanics of certifying and revoking public keys and escrow
© ACM, 2001. This is the authors' version of the work. It is posted here by permission of ACM for your personal use.Not for redistribution. The definitive version is available at http://doc.guandang.net/10.1145/503339.503343.
AnAuthorizationModelforaPublicKey
ManagementService
PIERANGELASAMARATI
Universit`adiMilano
MICHAELK.REITER
CarnegieMellonUniversity
and
SUSHILJAJODIA
GeorgeMasonUniversity
Publickeymanagementhasreceivedconsiderableattentionfromboththeresearchandcommercial
communitiesasausefulprimitiveforsecureelectroniccommerceandsecurecommunication.While
themechanicsofcertifyingandrevokingpublickeysandescrowingandrecoveringprivatekeys
havebeenwidelyexplored,lessattentionhasbeenpaidtoaccesscontrolframeworksforregulating
accesstostoredkeysbydifferentparties.Inthisarticleweproposesuchaframeworkforakey
managementservicethatsupportspublickeyregistration,lookup,andrevocation,andprivatekey
escrow,protecteduse(e.g.,todecryptselectedmessages),andrecovery.Weproposeanaccesscontrol
modelusingapolicybasedonprincipal,ownership,andauthorityrelationshipsonkeys.Themodel
allowsownerstogranttoothers(andrevoke)privilegestoexecutevariousactionsontheirkeys.
Thesimpleauthorizationlanguageisveryexpressive,enablingthespeci cationofauthorizations
forcompositesubjectsthatcanbefullyspeci ed(ground)orpartiallyspeci ed,thusmakingthe
authorizationsapplicabletoallsubjectssatisfyingsomeconditions.Weillustratehowtheaccess
controlpolicyandtheauthorizationscaneasilybeexpressedthroughasimpleandrestricted,hence
ef cientlycomputable,formoflogiclanguage.
CategoriesandSubjectDescriptors:D.4.6[OperatingSystems]:SecurityandProtection—Access
Controls;H.2.7[DatabaseManagement]:DatabaseAdministration—Security,integrity,andpro-
tection;K.6.5[ManagementofComputingandInformationSystems]:SecurityandProtection
GeneralTerms:Security
AdditionalKeyWordsandPhrases:Accesscontrol,authorizationsspeci cationandenforcement,
publickeyinfrastructure
TheworkofPierangelaSamaratiwaspartiallysupportedbytheEuropeanCommunitywithinthe
Fifth(EC)FrameworkProgrammeundercontractIST-1999-11791–FASTERproject.
Authors’addresses:PierangelaSamarati,DipartimentodiTecnologiedell’Informazione,Universit`a
diMilano,ViaBramante,65,26013Crema(CR),Italy;email:samarati@dsi.unimi.it;MichaelK.
Reiter,CarnegieMellonUniversity,Pittsburgh,PA15213;email:reiter@cmu.edu;SushilJajodia,
CenterforSecureInformationSystems,GeorgeMasonUniversity,Fairfax,VA22030-4444;email:
jajodia@gmu.edu.
Permissiontomakedigitalorhardcopiesofpartorallofthisworkforpersonalorclassroomuseis
grantedwithoutfeeprovidedthatcopiesarenotmadeordistributedforpro tordirectcommercial
advantageandthatcopiesshowthisnoticeonthe rstpageorinitialscreenofadisplayalong
withthefullcitation.CopyrightsforcomponentsofthisworkownedbyothersthanACMmustbe
honored.Abstractingwithcreditispermitted.Tocopyotherwise,torepublish,topostonservers,
toredistributetolists,ortouseanycomponentofthisworkinothersworks,requirespriorspeci c
permissionand/orafee.PermissionsmayberequestedfromPublicationsDept,ACMInc.,1515
Broadway,NewYork,NY10036USA,fax+1(212)869-0481,orpermissions@http://doc.guandang.net.
C2001ACM1094-9224/01/1100–0453$5.00
ACMTransactionsonInformationandSystemSecurity,Vol.4,No.4,November2001,Pages453–482.
Public key management has received considerable attention from both the research and commercial communities as a useful primitive for secure electronic commerce and secure communication. While the mechanics of certifying and revoking public keys and escrow
454 P.Samaratietal.
1.INTRODUCTION
Themechanicsofpublickeymanagement—i.e.,thecreationanddistributionofpublickeycerti catesandrevocationlists,andthesecurebackup(escrow)ofprivatekeys—hasbeenexploredextensively(e.g.,seeACM[1996]).However,muchlessattentionhasbeenpaidtotheauthorizationmodelthatmustsur-roundthesemechanisms.At rstglance,theauthorizationmodelseemsquitesimple:apublickeyshouldbeaccessibletoanyone,andanescrowedprivatekeyshouldbeaccessibleonlytoitsowners,astheirnamesindicates.Thissimplemodelis,however,fartoounderdevelopedformanyrealisticsettings.
—Onepurposeinescrowingaprivatekey,relevantmainlyinbusinesssettings,istodelegatetheauthoritytousethatkeytotheescrowingservice.Forexample,uponleavingforvacation,anexecutivemightescrowherprivatekeyattheserviceandauthorizethatitbeusedtodecryptmessagesuponrequestbyatleasttwoofherdirectreports.Whenshereturnsfromhervacation,shecancheckthelogsattheservicetoseewhatherkeywasusedtodecrypt.
—Itmaybedesirablethatsome“public”keysnotbepublicatall,butavailabletoonlyaselectedfewforverifyingsignaturesonprivatemessages.Inthisway,ifamessageisaccidentallyleakedfromanorganization,outsidersmuststillobtainacerti edverifyingkeytoprovethatthemessageactuallyorigi-natedfromwithintheorganization.Hiding“public”keyscanalsobeusefulforpreventingoutsidersfromsendingencryptedemailtotargetswithintheorganization.Encryptedemailcould,forinstance,beusedtoslipavirus-ladendocumentbyvirus-detectionsoftwareattheorganization’s rewall.—Theownerofapublickeymayconferrevocationauthoritytoothers,sothatoneofthemcanrevokethepublickeyiftheprivatekeyisstolenandtheowner’scopyisdestroyed.
Accesscontrolforpublickeymanagementservicesmustalsoaddressthepeculiaritiesofdealingwithkeysasobjectsofauthorizations.Inparticular,keysenjoyamoredynamicbehaviorthantraditionalobjects/resources,whichraisestheissueofhowkeysshouldbereferredto(e.g.,viatheirvaluesortheirprincipals).Also, …… 此处隐藏:45211字,全部文档内容请下载后查看。喜欢就下载吧 ……
- 基于PLC控制的航空电镀生产线自动输送
- 中考预测课内外文言文对比阅读2
- 2018-2023年中国商业智能(BI)产业市场
- 中国金融体制改革研究2011new
- 外窗淋水试验方案
- 精益生产(Lean Production)
- 学校安全事故处置和信息报送制度
- Chapter 5 Human Resources Management
- 【小学数学】人教版小学六年级上册数学
- 初中数学解题方法与技巧
- 山东省创伤中心建设与管理指导原则(试
- 函数与数列的极限的强化练习题答案
- 10分钟淋巴按摩消脂
- 网络应急演练预案
- 服装设计入门基础知识
- 初二数学分式计算题练习
- (人教新课标)高二数学必修5第二章 数列
- 最新自主创业项目
- 北京大学 无机化学课件 4第4章 配合物
- 贸易公司业务管理制度




