University of Wollongong
Browse

PERM: Practical reputation-based blacklisting without TTPs

Download (851.21 kB)
conference contribution
posted on 2024-11-14, 11:46 authored by Man Ho Allen Au, Apu Kapadia
Some users may misbehave under the cover of anonymity by, e.g., defacing webpages on Wikipedia or posting vulgar comments on YouTube. To prevent such abuse, a few anonymous credential schemes have been proposed that revoke access for misbehaving users while maintaining their anonymity such that no trusted third party (TTP) is involved in the revocation process. Recently we proposed BLACR, a TTP-free scheme that supports ‘reputation-based blacklisting’ — the service provider can score users’ anonymous sessions (e.g., good vs. inappropriate comments) and users with insufficient reputation are denied access. The major drawback of BLACR is the linear computational overhead in the size of the reputation list, which allows it to support reputation for only a few thousand user sessions in practical settings. We propose PERM, a revocationwindow- based scheme (misbehaviors must be caught within a window of time), which makes computation independent of the size of the reputation list. PERM thus supports millions of user sessions and makes reputation-based blacklisting practical for large-scale deployments.

History

Citation

Au, M. & Kapadia, A. (2012). PERM: Practical reputation-based blacklisting without TTPs. ACM Conference on Computer and Communications Security (pp. 929-940). United States of America: ACM.

Pagination

929-940

Language

English

RIS ID

72820

Usage metrics

    Categories

    Exports

    RefWorks
    BibTeX
    Ref. manager
    Endnote
    DataCite
    NLM
    DC