Proceedings of the First International Workshop on Security (IWSEC2006)
巻, 号, ページ
出版年月
2006年10月
出版者
和文:
英文:
会議名称
和文:
英文:
The First International Workshop on Security (IWSEC2006)
開催地
和文:
英文:
アブストラクト
Policy-Based Email System (PBES) is an email system which prevents the unintentional leakage of secrets in email environments. We argue that the two main reasons of such leakage are the implied policy in an email and the absence of the efficient mechanism for policy enforcement; they allow a receiver to misinterpret the sender's policy and handle the email content against it. This paper describes the design and our prototype implementation of PBES. The fundamental functions of PBES are codification of the secondary use policy of email content into XACML and its enforcement on receiver side. PBES also deals with the users' unintentional and unsafe actions which move email contents outside email environment, such as copy-and-paste. Since PBES distributes policy enforcement points in consideration with the exchange of emails among different organizations, it is suitable for wide-area use.