Skip to main navigation Skip to search Skip to main content

A trust assignment model based on alternate actions payoff

  • SUNY Buffalo

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

2 Scopus citations

Abstract

The human component is a determining factor in the success of the security subsystem. While security policies dictate the set of permissible actions of a user, best practices dictate the efficient mode of execution for these actions. Unfortunately, this efficient mode of execution is not always the easiest to carry out. Users, unaware of the implications of their actions, seek to carry out the easier mode of execution rather than the efficient one, thereby introducing a certain level of uncertainty unacceptable in high assurance information systems. In this paper, we present a dynamic trust assignment model that evaluates the system's trust on user actions over time. We first discuss the interpretation of trust in the context of the statement "the system trusts the users' actions" as opposed to "the system trusts the user." We then derive the intuition of our trust assignment framework from a game-theoretic model, where trust updates are performed through "compensatory transfer." For each efficient action by a user, we assign a trust value equal to the "best claim for compensation", defined as the maximum difference between the benefits of an alternate action and the selected efficient action by the user. The users' initial trust and recent actions are both taken into account and the user is appropriately rewarded or penalized through trust updates. The utility of such a model is two-fold: It helps the system to identify and educate users who consistently avoid (or are unaware of) implementing the organization's best practices and secondly, in the face of an action whose conformance to the organizational policies is contentious, it provides the system or a monitoring agent with a basis, viz. the trust level, to allow or disallow the action. Finally we demonstrate the application of this model in a Document Management System.

Original languageEnglish
Title of host publicationTrust Management - 4th International Conference, iTrust 2006, Proceedings
PublisherSpringer Verlag
Pages339-353
Number of pages15
ISBN (Print)3540342958, 9783540342953
DOIs
StatePublished - 2006
Event4th International Conference on Trust Management, iTrust 2006 - Pisa, Italy
Duration: May 16 2006May 19 2006

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume3986 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference4th International Conference on Trust Management, iTrust 2006
Country/TerritoryItaly
CityPisa
Period05/16/0605/19/06

Keywords

  • Compensatory Transfers
  • Document Management Systems
  • Trust Metrics

Fingerprint

Dive into the research topics of 'A trust assignment model based on alternate actions payoff'. Together they form a unique fingerprint.

Cite this