Title
TRAAC: Trust and risk aware access control
Abstract
Systems for allowing users to manage access to their personal data are important for a wide variety of applications including healthcare, where authorised individuals may need to share information in ways that the owner had not anticipated. Simply denying access in unknown cases may hamper critical decisions and affect service delivery. Rather, decisions can be made considering the risk of a given sharing request, and the trustworthiness of the requester. We propose a trust- and risk-aware access control mechanism (TRAAC) and a sparse zone-based policy model, which together allow decision-making on the basis of the requester's trustworthiness with regards to both the information to be shared, and the completion of obligations designed to mitigate risk. We formalise our approach and compare it with an existing approach that does not model trust through simulation.
Year
DOI
Venue
2014
10.1109/PST.2014.6890962
Privacy, Security and Trust
Keywords
Field
DocType
authorisation,decision making,risk analysis,trusted computing,TRAAC,decision making,sparse zone-based policy model,trust and risk aware access control
Health care,Internet privacy,Computer science,Trustworthiness,Computer security,Authorization,Access control,Service delivery framework
Conference
ISSN
Citations 
PageRank 
1712-364X
4
0.56
References 
Authors
13
4
Name
Order
Citations
PageRank
Chris Burnett11328.40
Liang Chen21167.56
Peter Edwards3219122.41
Timothy J. Norman41417140.04