【24h】

Data-Minimizing Authentication Goes Mobile

机译:数据最少的身份验证可移动

获取原文

摘要

Authentication is a prerequisite for proper access control to many e-services. Often, it is carried out by identifying the user, while generally, verification of certified attributes would suffice. Even worse, this kind of authentication makes all the user's transactions linkable and discloses an excessive amount of personal information, and thus erodes the user's privacy. This is in clear contradiction to the data minimization principle put forth in the European data protection legislation. In this paper, we present data-minimizing mobile authentication, which is a kind of attribute-based authentication through the use of anonymous credentials, thereby revealing substantially less personal information about the user. We describe two typical scenarios, design an architecture, and discuss a prototype implemented on a smart phone which minimizes the disclosure of personal data in a user-to-terminal authentication setting. The prototype uses the Identity Mixer anonymous credential system (Idemix) and realizes short-range communication between the smart phone and the terminal using visual channels over which QR codes are exchanged. Furthermore, the security has been improved and unauthorized sharing of credentials prevented by storing the credentials' secret key in a secure element hosted by the mobile phone. Our measurements show that the use of smart phones for data-minimizing authentication can be an actual "game changer" for a broad deployment of anonymous credential systems.
机译:身份验证是对许多电子服务进行适当访问控制的先决条件。通常,它是通过识别用户来执行的,而通常,对认证属性的验证就足够了。更糟糕的是,这种身份验证使所有用户的交易都可链接,并泄露了过多的个人信息,从而侵蚀了用户的隐私。这与欧洲数据保护法规中提出的数据最小化原则明显矛盾。在本文中,我们提出了数据最小化移动身份验证,这是一种通过使用匿名凭据的基于属性的身份验证,从而揭示了关于用户的个人信息大大减少了。我们描述了两个典型的场景,设计了一个体系结构,并讨论了在智能手机上实现的原型,该原型在用户到终端的身份验证设置中最大程度地减少了个人数据的泄露。该原型使用Identity Mixer匿名证书系统(Idemix),并使用可视信道交换QR码,从而实现了智能手机与终端之间的短距离通信。此外,通过将凭证的秘密密钥存储在由移动电话托管的安全元件中,安全性得到了改善并且防止了凭证的未授权共享。我们的测量结果表明,使用智能手机进行数据最小化身份验证对于匿名证书系统的广泛部署可能是真正的“游戏规则改变者”。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号