학술논문

Enforcing Expressive Accountability Policies
Document Type
Conference
Source
2014 IEEE 23rd International WETICE Conference WETICE Conference (WETICE), 2014 IEEE 23rd International. :333-338 Jun, 2014
Subject
Computing and Processing
Authorization
Context
Authentication
Cloud computing
Protocols
Servers
Accountability
Policy definition and enforcement
Cross-domain and multi-level policies
Security in social networks
Oauth
Language
ISSN
1524-4547
Abstract
Accountability policies for the enforcement of the responsible stewardship of personal data have to support the gathering of information at all levels of the service stack and across different policy domains, for instance, for the retrospective enforcement of transparency and remediation properties. Existing approaches to accountability, however, often do not meet these requirements and corresponding implementation support is lacking. In this paper we show how expressive accountability policies can be defined in terms of policy domains, accessible data at all levels of the service stack, and preventive and retrospective mechanisms. Additionally, we present a notion of accountability schemes that support the constructive implementation of our accountability policies. Finally, we motivate and apply our approach in the context of real-world attacks to OAuth-based authorization and authentication protocols.