학술논문

Cryptographically Enforced Four-Eyes Principle
Document Type
Conference
Source
2016 11th International Conference on Availability, Reliability and Security (ARES) Availability, Reliability and Security (ARES), 2016 11th International Conference on. :760-767 Aug, 2016
Subject
Computing and Processing
Public key
Standards
Digital signatures
Servers
Aggregates
Language
Abstract
The 4-eyes principle (4EP) is a well-known access control and authorization principle, and used in many scenarios to minimize the likelihood of corruption. It states that at least two separate entities must approve a message before it is considered authentic. Hence, an adversarial party aiming to forge bogus content is forced to convince other parties to collude in the attack. We present a formal framework along with a suitable security model. Namely, a party sets a policy for a given message which involves multiple additional approvers in order to authenticate the message. Finally, we show how these signatures are black-box realized by secure sanitizable signature schemes.