Practical Decentralized Attribute-Based Delegation using Secure Name Systems

05/16/2018
by   Martin Schanzenbach, et al.
0

Identity and trust in the modern Internet are centralized around an oligopoly of identity service providers consisting solely of major tech companies. The problem with centralizing trust has become evident in recent discoveries of mass surveillance and censorship programs as well as information leakage through hacking incidents. One approach to decentralizing trust is distributed, attribute-based access control via attribute-based delegation (ABD). Attribute-based delegation allows a large number of cross-domain attribute issuers to be used in making authorization decisions. Attributes are not only issued to identities, but can also be delegated to other attributes issued by different entities in the system. The resulting trust chains can then be resolved by any entity given an appropriate attribute storage and resolution system. While current proposals often fail at the practicability, we show how attribute-based delegation can be realized on top of the secure GNU Name System (GNS) to solve an authorization problem in a real-world scenario.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
05/16/2018

reclaimID: Secure, Self-Sovereign Identities using Name Systems and Attribute-Based Encryption

In this paper we present reclaimID: An architecture that allows users to...
research
02/08/2020

Data User-Based Attribute-Based Encryption

Attribute-Based Encryption (ABE) has emerged as an information-centric p...
research
09/22/2022

Zero Trust Federation: Sharing Context under User Control toward Zero Trust in Identity Federation

To securely control access to systems, the concept of Zero Trust has bee...
research
03/01/2022

Towards Decentralized Identity Management in Multi-stakeholder 6G Networks

Trust-building mechanisms among network entities of different administra...
research
02/16/2022

Data Capsule: A Self-Contained Data Model as an Access Policy Enforcement Strategy

In this paper, we introduce a data capsule model, a self-contained and s...
research
08/08/2022

A Tutorial on the Interoperability of Self-sovereign Identities

Self-sovereign identity is the latest digital identity paradigm that all...
research
01/17/2023

The Universal Trust Machine: A survey on the Web3 path towards enabling long term digital cooperation through decentralised trust

Since the dawn of human civilization, trust has been the core challenge ...

Please sign up or login with your details

Forgot password? Click here to reset