Risk assessment in distributed authorization

  • Authors:
  • Peter Chapin;Christian Skalka;X. Sean Wang

  • Affiliations:
  • University of Vermont;University of Vermont;University of Vermont

  • Venue:
  • Proceedings of the 2005 ACM workshop on Formal methods in security engineering
  • Year:
  • 2005

Quantified Score

Hi-index 0.00

Visualization

Abstract

Distributed authorization takes into account several elements, including certificates that may be provided by non-local actors. While most trust management systems treat all assertions as equally valid up to certificate authentication, realistic considerations may associate risk with some of these elements; some actors may be less trusted than others, some elements may be more computationally expensive to obtain, and so forth. Furthermore, practical online authorization may require certain levels of risk to be tolerated. In this paper, we introduce a trust management logic that incorporates formal risk assessment. This formalization allows risk levels to be associated with authorization elements, and promotes development of a distributed authorization algorithm allowing tolerable levels of risk to be precisely specified and rigorously enforced.