Exploring Reciprocal Exchanges and Trust-Based Authorizations: A Feasibility Demonstration with Location-Based Services
摘要
There is a large body of evidence in fields like psychology and sociology indicating that reciprocity is a powerful determinant of human behavior. However, none of the existing access control models captures this reciprocity phenomenon. In this paper, we introduce a new decision-type, which we call reciprocal, to by which users grant access to their resources only to those other users who allow them reciprocal access. We define the syntax and semantics of reciprocal authorizations and show how to include this new decision-type in the Attribute-Based Access Control model. We use location-based services as an example to deploy reciprocal authorizations; we propose two approaches to integrate them into these services and analyze their soundness and complexity. Next, we prove the soundness and analyze the complexity of both approaches. We also study how the ratio of reciprocal to allow and to deny authorizations affects the number of persons whose position a given person may read. These ratios may help in predicting whether users are willing to use reciprocal authorizations instead of deny or allow. Experiments confirm our complexity analyses and shed light on the performance of our approaches.