{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T04:53:28Z","timestamp":1750308808407,"version":"3.41.0"},"reference-count":50,"publisher":"Association for Computing Machinery (ACM)","issue":"1","license":[{"start":{"date-parts":[[2009,10,1]],"date-time":"2009-10-01T00:00:00Z","timestamp":1254355200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000145","name":"Division of Information and Intelligent Systems","doi-asserted-by":"publisher","award":["IIS-0430274CCR-0325951"],"award-info":[{"award-number":["IIS-0430274CCR-0325951"]}],"id":[{"id":"10.13039\/100000145","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["IIS-0430274CCR-0325951"],"award-info":[{"award-number":["IIS-0430274CCR-0325951"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Inf. Syst. Secur."],"published-print":{"date-parts":[[2009,10]]},"abstract":"<jats:p>In automated trust negotiation (ATN), two parties exchange digitally signed credentials that contain attribute information to establish trust and make access control decisions. Because the information in question is often sensitive, credentials are protected according to access control policies. In traditional ATN, credentials are transmitted either in their entirety or not at all. This approach can at times fail unnecessarily, either because a cyclic dependency makes neither negotiator willing to reveal her credential before her opponent because the opponent must be authorized for all attributes packaged together in a credential to receive any of them, or because it is necessary to disclose the precise attribute values, rather than merely proving they satisfy some predicate (such as being over 21 years of age). Recently, several cryptographic credential schemes and associated protocols have been developed to address these and other problems. However, they can be used only as fragments of an ATN process. This article introduces a framework for ATN in which the diverse credential schemes and protocols can be combined, integrated, and used as needed. A policy language is introduced that enables negotiators to specify authorization requirements that must be met by an opponent to receive various amounts of information about certified attributes and the credentials that contain it. The language also supports the use of uncertified attributes, allowing them to be required as part of policy satisfaction, and to place their (automatic) disclosure under policy control.<\/jats:p>","DOI":"10.1145\/1609956.1609958","type":"journal-article","created":{"date-parts":[[2009,11,4]],"date-time":"2009-11-04T18:28:31Z","timestamp":1257359311000},"page":"1-35","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":14,"title":["Automated trust negotiation using cryptographic credentials"],"prefix":"10.1145","volume":"13","author":[{"given":"Jiangtao","family":"Li","sequence":"first","affiliation":[{"name":"Intel Corporation, Hillsboro, OR"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ninghui","family":"Li","sequence":"additional","affiliation":[{"name":"Purdue University, West Lafayette, IN"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"William H.","family":"Winsborough","sequence":"additional","affiliation":[{"name":"University of Texas at San Antonio, San Antonio, TX"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2009,11,6]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1007\/11507840_7"},{"volume-title":"Proceedings of the IEEE Symposium on Security and Privacy. IEEE","author":"Balfanz D.","key":"e_1_2_1_2_1","unstructured":"Balfanz , D. , Durfee , G. , Shankar , N. , Smetters , D. , Staddon , J. , and Wong , H . -C. 2003. Secret handshakes from pairing-based key agreements . In Proceedings of the IEEE Symposium on Security and Privacy. IEEE , Los Alamitos, CA, 180--196. Balfanz, D., Durfee, G., Shankar, N., Smetters, D., Staddon, J., and Wong, H.-C. 2003. Secret handshakes from pairing-based key agreements. In Proceedings of the IEEE Symposium on Security and Privacy. IEEE, Los Alamitos, CA, 180--196."},{"key":"e_1_2_1_3_1","doi-asserted-by":"crossref","unstructured":"Blaze M. Feigenbaum J. Ioannidis J. and Keromytis A. D. 1999. The KeyNote Trust-Management System version 2. IETF RFC 2704. http:\/\/www.cis.upenn.edu\/~angelos\/Papers\/rfc2704.txt.  Blaze M. Feigenbaum J. Ioannidis J. and Keromytis A. D. 1999. The KeyNote Trust-Management System version 2. IETF RFC 2704. http:\/\/www.cis.upenn.edu\/~angelos\/Papers\/rfc2704.txt.","DOI":"10.17487\/rfc2704"},{"volume-title":"Proceedings of the IEEE Symposium on Security and Privacy. IEEE","author":"Blaze M.","key":"e_1_2_1_4_1","unstructured":"Blaze , M. , Feigenbaum , J. , and Lacy , J . 1996. Decentralized trust management . In Proceedings of the IEEE Symposium on Security and Privacy. IEEE , Los Alamitos, CA, 164--173. Blaze, M., Feigenbaum, J., and Lacy, J. 1996. Decentralized trust management. In Proceedings of the IEEE Symposium on Security and Privacy. IEEE, Los Alamitos, CA, 164--173."},{"key":"e_1_2_1_5_1","doi-asserted-by":"crossref","unstructured":"Boeyen S. Howes T. and Richard P. 1999. Internet X.509 Public Key Infrastructure LDAPc2 Schema. IETF RFC 2587.  Boeyen S. Howes T. and Richard P. 1999. Internet X.509 Public Key Infrastructure LDAPc2 Schema. IETF RFC 2587.","DOI":"10.17487\/rfc2587"},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/352600.352620"},{"volume-title":"Advances in Cryptology (EUROCRYPT'00)","author":"Boudot F.","key":"e_1_2_1_7_1","unstructured":"Boudot , F. 2000. Efficient proofs that a committed number lies in an interval . In Advances in Cryptology (EUROCRYPT'00) . Springer , Berlin , 431--444. Boudot, F. 2000. Efficient proofs that a committed number lies in an interval. In Advances in Cryptology (EUROCRYPT'00). Springer, Berlin, 431--444."},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/1030083.1030104"},{"volume-title":"Rethinking Public Key Infrastructures and Digital Certificates: Building in Privacy","author":"Brands S. A.","key":"e_1_2_1_9_1","unstructured":"Brands , S. A. 2000. Rethinking Public Key Infrastructures and Digital Certificates: Building in Privacy . MIT Press , Cambridge, MA . Brands, S. A. 2000. Rethinking Public Key Infrastructures and Digital Certificates: Building in Privacy. MIT Press, Cambridge, MA."},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/586110.586114"},{"key":"e_1_2_1_11_1","doi-asserted-by":"crossref","unstructured":"Camenisch J. and Lysyanskaya A. 2001. An efficient system for non-transferable anonymous credentials with optional anonymity revocation. In Advances in Cryptology (EUROCRYPT'01). Springer Berlin 93--118.   Camenisch J. and Lysyanskaya A. 2001. An efficient system for non-transferable anonymous credentials with optional anonymity revocation. In Advances in Cryptology (EUROCRYPT'01). Springer Berlin 93--118.","DOI":"10.1007\/3-540-44987-6_7"},{"key":"e_1_2_1_12_1","doi-asserted-by":"crossref","unstructured":"Castelluccia C. Jarecki S. and Tsudik G. 2004. Secret handshakes from CA-oblivious encryption. In Advances in Cryptology (ASIACRYPT'04). Springer Berlin 293--307.  Castelluccia C. Jarecki S. and Tsudik G. 2004. Secret handshakes from CA-oblivious encryption. In Advances in Cryptology (ASIACRYPT'04). Springer Berlin 293--307.","DOI":"10.1007\/978-3-540-30539-2_21"},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/4372.4373"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.5555\/512756.512758"},{"key":"e_1_2_1_15_1","doi-asserted-by":"crossref","unstructured":"Cramer R. and Damg\u00e5rd I. 1998. Zero-knowledge proof for finite field arithmetic or: Can zero-knowledge be for free&amp;quest; In Advances in Cryptology (CRYPTO'98). Springer Berlin 424--441.   Cramer R. and Damg\u00e5rd I. 1998. Zero-knowledge proof for finite field arithmetic or: Can zero-knowledge be for free&amp;quest; In Advances in Cryptology (CRYPTO'98). Springer Berlin 424--441.","DOI":"10.1007\/BFb0055745"},{"key":"e_1_2_1_16_1","doi-asserted-by":"crossref","unstructured":"Cramer R. Franklin M. K. Schoenmakers B. and Yung M. 1996. Multi-authority secret-ballot elections with linear work. In Advances in Cryptology (EUROCRYPT'96). Springer Berlin 72--83.   Cramer R. Franklin M. K. Schoenmakers B. and Yung M. 1996. Multi-authority secret-ballot elections with linear work. In Advances in Cryptology (EUROCRYPT'96). Springer Berlin 72--83.","DOI":"10.1007\/3-540-68339-9_7"},{"key":"e_1_2_1_17_1","doi-asserted-by":"crossref","unstructured":"Damg\u00e5rd I. and Fujisaki E. 2002. An integer commitment scheme based on groups with hidden order. In Advances in Cryptology (ASIACRYPT'02). Springer Berlin 125--142.   Damg\u00e5rd I. and Fujisaki E. 2002. An integer commitment scheme based on groups with hidden order. In Advances in Cryptology (ASIACRYPT'02). Springer Berlin 125--142.","DOI":"10.1007\/3-540-36178-2_8"},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.5555\/829514.830540"},{"key":"e_1_2_1_19_1","doi-asserted-by":"crossref","unstructured":"Dodis Y. Kiayias A. Nicolosi A. and Shoup V. 2004. Anonymous identification in ad hoc groups. In Advances in Cryptology (EUROCRYPT'04). Springer Berlin 609--626.  Dodis Y. Kiayias A. Nicolosi A. and Shoup V. 2004. Anonymous identification in ad hoc groups. In Advances in Cryptology (EUROCRYPT'04). Springer Berlin 609--626.","DOI":"10.1007\/978-3-540-24676-3_36"},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/352600.352610"},{"key":"e_1_2_1_21_1","doi-asserted-by":"crossref","unstructured":"Ellison C. Frantz B. Lampson B. Rivest R. Thomas B. and Ylonen T. 1999. SPKI certificate theory. IETF RFC 2693.  Ellison C. Frantz B. Lampson B. Rivest R. Thomas B. and Ylonen T. 1999. SPKI certificate theory. IETF RFC 2693.","DOI":"10.17487\/rfc2693"},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/1029179.1029186"},{"volume-title":"Proceedings of 13th Network and Distributed System Security Symposium. ISOC","author":"Frikken K. B.","key":"e_1_2_1_23_1","unstructured":"Frikken , K. B. , Li , J. , and Atallah , M. J . 2006. Trust negotiation with hidden credentials, hidden policies, and policy cycles . In Proceedings of 13th Network and Distributed System Security Symposium. ISOC , Reston, VA, 157--172. Frikken, K. B., Li, J., and Atallah, M. J. 2006. Trust negotiation with hidden credentials, hidden policies, and policy cycles. In Proceedings of 13th Network and Distributed System Security Symposium. ISOC, Reston, VA, 157--172."},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.5555\/365950.365956"},{"volume-title":"Proceedings of the Network and Distributed System Security Symposium. ISOC","author":"Hess A.","key":"e_1_2_1_25_1","unstructured":"Hess , A. , Jacobson , J. , Mills , H. , Wamsley , R. , Seamons , K. E. , and Smith , B . 2002. Advanced client\/server authentication in TLS . In Proceedings of the Network and Distributed System Security Symposium. ISOC , Reston, VA, 203--214. Hess, A., Jacobson, J., Mills, H., Wamsley, R., Seamons, K. E., and Smith, B. 2002. Advanced client\/server authentication in TLS. In Proceedings of the Network and Distributed System Security Symposium. ISOC, Reston, VA, 203--214."},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/1005140.1005142"},{"key":"e_1_2_1_27_1","doi-asserted-by":"crossref","unstructured":"Housley R. Ford W. Polk T. and Solo D. 1999. Internet X.509 public key infrastructure certificate and CRL profile. IETF RFC 2459.  Housley R. Ford W. Polk T. and Solo D. 1999. Internet X.509 public key infrastructure certificate and CRL profile. IETF RFC 2459.","DOI":"10.17487\/rfc2459"},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/1102120.1102128"},{"key":"e_1_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.5555\/882495.884431"},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1007\/11496137_21"},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/1073814.1073819"},{"key":"e_1_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/872035.872061"},{"key":"e_1_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/605434.605438"},{"volume-title":"Proceedings of the 5th International Symposium on Practical Aspects of Declarative Languages. Springer","author":"Li N.","key":"e_1_2_1_34_1","unstructured":"Li , N. and Mitchell , J. C . 2003. Datalog with constraints: A foundation for trust management languages . In Proceedings of the 5th International Symposium on Practical Aspects of Declarative Languages. Springer , Berlin, 58--73. Li, N. and Mitchell, J. C. 2003. Datalog with constraints: A foundation for trust management languages. In Proceedings of the 5th International Symposium on Practical Aspects of Declarative Languages. Springer, Berlin, 58--73."},{"volume-title":"Proceedings of the IEEE Symposium on Security and Privacy. IEEE","author":"Li N.","key":"e_1_2_1_35_1","unstructured":"Li , N. , Mitchell , J. C. , and Winsborough , W. H . 2002. Design of a role-based trust management framework . In Proceedings of the IEEE Symposium on Security and Privacy. IEEE , Los Alamitos, CA, 114--130. Li, N., Mitchell, J. C., and Winsborough, W. H. 2002. Design of a role-based trust management framework. In Proceedings of the IEEE Symposium on Security and Privacy. IEEE, Los Alamitos, CA, 114--130."},{"key":"e_1_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.5555\/773065.773067"},{"volume-title":"Proceedings of the 6th Workshop on Selected Areas in Cryptography. Springer","author":"Lysyanskaya A.","key":"e_1_2_1_37_1","unstructured":"Lysyanskaya , A. , Rivest , R. L. , Sahai , A. , and Wolf , S . 1999. Pseudonym systems . In Proceedings of the 6th Workshop on Selected Areas in Cryptography. Springer , Berlin, 184--199. Lysyanskaya, A., Rivest, R. L., Sahai, A., and Wolf, S. 1999. Pseudonym systems. In Proceedings of the 6th Workshop on Selected Areas in Cryptography. Springer, Berlin, 184--199."},{"volume-title":"Advances in Cryptology (CRYPTO'91)","author":"Pedersen T. P.","key":"e_1_2_1_38_1","unstructured":"Pedersen , T. P. 1991. Non-interactive and information-theoretic secure verifiable secret sharing . In Advances in Cryptology (CRYPTO'91) . Springer , Berlin , 129--140. Pedersen, T. P. 1991. Non-interactive and information-theoretic secure verifiable secret sharing. In Advances in Cryptology (CRYPTO'91). Springer, Berlin, 129--140."},{"key":"e_1_2_1_39_1","volume-title":"SDSI: A Simple Distributed Security Infrastructure","author":"Rivest R. L.","year":"1996","unstructured":"Rivest , R. L. and Lampson , B . 1996 . SDSI: A Simple Distributed Security Infrastructure . http:\/\/groups.csail.mit.edu\/cis\/sdsi.html. Rivest, R. L. and Lampson, B. 1996. SDSI: A Simple Distributed Security Infrastructure. http:\/\/groups.csail.mit.edu\/cis\/sdsi.html."},{"volume-title":"Proceedings of the Symposium on Network and Distributed System Security. ISOC","author":"Seamons K. E.","key":"e_1_2_1_40_1","unstructured":"Seamons , K. E. , Winslett , M. , and Yu , T . 2001. Limiting the disclosure of access control policies during automated trust negotiation . In Proceedings of the Symposium on Network and Distributed System Security. ISOC , Reston, VA. Seamons, K. E., Winslett, M., and Yu, T. 2001. Limiting the disclosure of access control policies during automated trust negotiation. In Proceedings of the Symposium on Network and Distributed System Security. ISOC, Reston, VA."},{"volume-title":"Proceedings of the 2nd Workshop on Privacy Enhancing Technologies. Springer-Verlag","author":"Seamons K. E.","key":"e_1_2_1_41_1","unstructured":"Seamons , K. E. , Winslett , M. , Yu , T. , Yu , L. , and Jarvis , R . 2002. Protecting privacy during online trust negotiation . In Proceedings of the 2nd Workshop on Privacy Enhancing Technologies. Springer-Verlag , Berlin. Seamons, K. E., Winslett, M., Yu, T., Yu, L., and Jarvis, R. 2002. Protecting privacy during online trust negotiation. In Proceedings of the 2nd Workshop on Privacy Enhancing Technologies. Springer-Verlag, Berlin."},{"key":"e_1_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.5555\/1767011.1767023"},{"key":"e_1_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/644527.644532"},{"volume-title":"Proceedings of the 3rd International Workshop on Policies for Distributed Systems and Networks. IEEE","author":"Winsborough W. H.","key":"e_1_2_1_44_1","unstructured":"Winsborough , W. H. and Li , N . 2002b. Towards practical automated trust negotiation . In Proceedings of the 3rd International Workshop on Policies for Distributed Systems and Networks. IEEE , Los Alamitos, CA, 92--103. Winsborough, W. H. and Li, N. 2002b. Towards practical automated trust negotiation. In Proceedings of the 3rd International Workshop on Policies for Distributed Systems and Networks. IEEE, Los Alamitos, CA, 92--103."},{"volume-title":"Proceedings of the IEEE Symposium on Security and Privacy. IEEE","author":"Winsborough W. H.","key":"e_1_2_1_45_1","unstructured":"Winsborough , W. H. and Li , N . 2004. Safety in automated trust negotiation . In Proceedings of the IEEE Symposium on Security and Privacy. IEEE , Los Alamitos, CA, 147--160. Winsborough, W. H. and Li, N. 2004. Safety in automated trust negotiation. In Proceedings of the IEEE Symposium on Security and Privacy. IEEE, Los Alamitos, CA, 147--160."},{"volume-title":"Proceedings of the DARPA Information Survivability Conference and Exposition. IEEE","author":"Winsborough W. H.","key":"e_1_2_1_46_1","unstructured":"Winsborough , W. H. , Seamons , K. E. , and Jones , V. E . 2000. Automated trust negotiation . In Proceedings of the DARPA Information Survivability Conference and Exposition. IEEE , Los Alamitos, CA, 88--102. Winsborough, W. H., Seamons, K. E., and Jones, V. E. 2000. Automated trust negotiation. In Proceedings of the DARPA Information Survivability Conference and Exposition. IEEE, Los Alamitos, CA, 88--102."},{"key":"e_1_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1109\/MIC.2002.1067734"},{"key":"e_1_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1145\/1005140.1005143"},{"volume-title":"Proceedings of IEEE Symposium on Security and Privacy. IEEE","author":"Yu T.","key":"e_1_2_1_49_1","unstructured":"Yu , T. and Winslett , M . 2003b. Unified scheme for resource protection in automated trust negotiation . In Proceedings of IEEE Symposium on Security and Privacy. IEEE , Los Alamitos, CA, 110--122. Yu, T. and Winslett, M. 2003b. Unified scheme for resource protection in automated trust negotiation. In Proceedings of IEEE Symposium on Security and Privacy. IEEE, Los Alamitos, CA, 110--122."},{"key":"e_1_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1145\/605434.605435"}],"container-title":["ACM Transactions on Information and System Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1609956.1609958","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1609956.1609958","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T20:26:14Z","timestamp":1750278374000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1609956.1609958"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2009,10]]},"references-count":50,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2009,10]]}},"alternative-id":["10.1145\/1609956.1609958"],"URL":"https:\/\/doi.org\/10.1145\/1609956.1609958","relation":{},"ISSN":["1094-9224","1557-7406"],"issn-type":[{"type":"print","value":"1094-9224"},{"type":"electronic","value":"1557-7406"}],"subject":[],"published":{"date-parts":[[2009,10]]},"assertion":[{"value":"2006-02-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2007-08-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2009-11-06","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}